TeamPCP supply chain attack hit LiteLLM users with malware

Forcepoint says the TeamPCP threat group used a supply chain attack to turn two LiteLLM PyPI releases into credential-stealing malware. The malicious code targeted cloud and AI credentials, including keys for OpenAI, Anthropic, Microsoft Azure, AWS and Google Cloud.

TeamPCP supply chain attack hit LiteLLM users with malware

Forcepoint’s X-Labs says a supply chain attack on LiteLLM, a widely used open-source Python library, turned two published releases into malware designed to steal cloud and AI credentials. The company attributed the campaign to a threat actor group it tracks as TeamPCP.

According to the report, the malicious versions were 1.82.7 and 1.82.8, both pushed to the Python Package Index, or PyPI, which is the main repository many Python users rely on to install packages. LiteLLM acts as a unified gateway to more than 100 large language model providers, so a compromise of the library had the potential to expose credentials across multiple AI services at once.

⚡ New to this?

This is a software supply chain attack, which means attackers didn’t just break into one company. They slipped malicious code into a tool other developers trust, and that code then stole secrets from systems that used it. A package like LiteLLM sits between apps and AI providers, so one bad dependency can expose access to several services at once.

🦞 OpenClaw angle

Treat AI gateway libraries and build-time security tools as high-value dependencies, not routine utilities. Lock down package installs with pinned versions, internal mirrors, and checksum verification, and monitor for unexpected PyPI publishes or dependency changes in CI/CD. Also separate publish tokens from build runners so a compromised scanner or test job cannot steal credentials that can release packages.

Forcepoint said the attackers did not breach LiteLLM’s source code repository directly. Instead, they reached the package through its build pipeline after first compromising Trivy, an open-source vulnerability scanner used in LiteLLM’s continuous integration and continuous delivery workflow.

The company said TeamPCP previously took over Trivy by spoofing legitimate maintainer identities and pushing impersonated commits. It then used Trivy’s own automated release process to distribute backdoored binaries through GitHub Releases, Docker Hub and Amazon ECR.

When LiteLLM’s CI/CD job pulled the compromised Trivy build, the malicious binary scraped memory from the build runner and stole a PYPI_PUBLISH token. Forcepoint said the attackers used that token to publish their own LiteLLM releases directly to PyPI.

The two malicious LiteLLM versions used different ways to execute their payloads. Version 1.82.7 included a Base64-encoded payload inside proxy_server.py, which ran when the LiteLLM proxy started. Version 1.82.8 used a quieter method, dropping a litelllm_init.pth file into site-packages so the payload would run every time the Python interpreter started, even if LiteLLM was never imported.

Forcepoint said a normal pip install of the tainted release was enough to trigger the malware. Once active, the payload searched environment variables and configuration files for credentials tied to OpenAI, Anthropic and Microsoft Azure, along with Amazon Web Services, Google Cloud and Azure SDK credentials. It also looked for kubeconfig files and AWS credential files in users’ home directories.

The stolen data was encrypted using AES-256-CBC with a 32-byte session key derived through PBKDF2, then packed into a file named tpcp.tar.gz and sent out with curl to models.litellm.cloud, which Forcepoint described as an attacker-controlled lookalike domain.

The report says the malware also installed a persistence component called Sysmon.py. On first run it sleeps for 300 seconds, then checks checkmarx.zone every 50 minutes for new instructions, downloads any returned binary to /tmp/pglog and runs it as a background process.

Prashant Kumar, senior researcher at Forcepoint X-Labs, said the campaign is especially dangerous for AI and ML teams because LiteLLM sits in front of major AI providers. “A single compromise gave attackers simultaneous access to OpenAI, Anthropic and Azure credentials,” he wrote, adding that losing one library could mean losing access control across several connected AI providers at once.

The incident echoes a separate investigation by Datadog Security Labs in March, which linked the same TeamPCP campaign to a malicious PyPI package targeting Telnyx’s Python SDK. In a guest column for SiliconANGLE last week, Secure Code Warrior CTO Matias Madou argued that the Datadog case was the first successful weaponization of security and developer infrastructure with elevated access privileges. Forcepoint’s findings add another example of how attacker-controlled packages can be used to reach sensitive credentials through software supply chains.

Source: SiliconANGLE ↗

More from Security News