gbhackers.com • 34m
LiteLLM Supply Chain Attack: Massive CI/CD Secret Exfiltration via Poisoned PyPI Releases
In March 2026, a supply chain attack targeting the LiteLLM Python library and proxy server utilized two malicious PyPI releases to facilitate credential theft. The attack, attributed to the "TeamPCP" campaign, was enabled by a poisoned security scanner that allowed malicious code to be distributed for a 40-minute window. The payload targeted CI/CD pipelines to harvest cloud keys, SSH keys, Kubernetes tokens, and database credentials. This resulted in the exfiltration of a 153GB archive containing approximately 434,000 files and 118,829 CI runner dumps, impacting 2,488 organizations across the technology, financial, and telecommunications sectors.