Robuta

Sponsor of the Day: Jerkmate
https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/ LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign | Datadog... On March 24 and 27, 2026, malicious PyPI releases of LiteLLM and Telnyx were published as part of the TeamPCP supply chain campaign. We trace the full campaign... teampcp supply chainlitellmtelnyxcompromisedpypi https://www.helpnetsecurity.com/2026/03/25/teampcp-supply-chain-attacks/ LiteLLM PyPI packages compromised in expanding TeamPCP supply chain attacks - Help Net Security Mar 27, 2026 - A slew of supply chain attacks against popular open source tools and packages appears to have been orchestrated by TeamPCP cybercriminals. teampcp supply chainlitellm pypipackages compromisedattacks helpexpanding https://ramimac.me/teampcp/ Incident Timeline // TeamPCP Supply Chain Campaign Apr 7, 2026 - Timeline and IOCs for TeamPCP's March 2026 supply chain campaign. Trivy, KICS, LiteLLM, and 45+ npm packages compromised through chained credential theft. teampcp supply chainincidenttimelinecampaign https://www.sans.org/white-papers/when-security-scanner-became-weapon When the Security Scanner Became the Weapon: TeamPCP Supply Chain TTP Report | SANS Institute Download the TeamPCP threat intelligence report. Analyze a real-world supply chain attack across CI/CD, cloud, and AI systems with TTPs, IOCs, and actionable... teampcp supply chainsecurity scannersans institutebecameweapon https://www.sans.org/blog/when-security-scanner-became-weapon-inside-teampcp-supply-chain-campaign When the Security Scanner Became the Weapon: Inside the TeamPCP Supply Chain Campaign | SANS... Mar 26, 2026 - A trusted security scanner was weaponized. One stolen token cascaded across five ecosystems—CI/CD, npm, Docker, and AI infrastructure. The TeamPCP campaign... teampcp supply chainsecurity scannerbecameweaponinside https://www.infosecurity-magazine.com/news/teampcp-exploit-stolen-supply/ TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets - Infosecurity Magazine Apr 3, 2026 - TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ and Vect ransomware gangs supply chaininfosecurity magazineteampcpexploresways https://www.infosecurity-magazine.com/news/teampcp-litellm-pypi-supply-chain/ TeamPCP Expands Supply Chain Campaign With LiteLLM PyPI Compromise - Infosecurity Magazine Apr 9, 2026 - Python package LiteLLM compromised with credential-stealing malware linked to TeamPCP threat group supply chain campaignlitellm pypiinfosecurity magazineteampcpexpands https://phoenix.security/teampcp-litellm-supply-chain-compromise-pypi-credential-stealer-kubernetes/ LiteLLM Backdoored by TeamPCP: PyPI Supply Chain Attack (2026) Mar 30, 2026 - TeamPCP backdoored LiteLLM v1.82.7 and v1.82.8 on PyPI with a credential stealer, K8s lateral movement, and persistent backdoor. Full IOCs, detection, and... pypi supply chainattack 2026litellmbackdooredteampcp