TeamPCP compromises Python libraries via supply chain attack

TL;DR AI
2 min readKey summary
Attackers spoofed Trivy maintainer activity and shipped a malicious Trivy release.
The fake release stole LiteLLM’s PyPI publish token from CI/CD memory, then enabled two backdoored LiteLLM versions on PyPI.
The malicious LiteLLM builds exfiltrated secrets and could persist on affected systems, impacting cloud and AI credentials.
The compromise of LiteLLM’s build and distribution chain creates broad downstream risk for users of OpenAI, Anthropic, Azure, AWS, and GCP.
