security
May 18, 2026
By Teun
TeamPCP supply chain attack hit LiteLLM users with malware
Forcepoint says the TeamPCP threat group used a supply chain attack to turn two LiteLLM PyPI releases into credential-stealing malware. The malicious code targeted cloud and AI credentials, including keys for OpenAI, Anthropic, Microsoft Azure, AWS and Google Cloud.
Forcepoint’s X-Labs says a supply chain attack on LiteLLM, a widely used open-source Python library, turned two published releases into malware designed to steal cloud and AI credentials. The company attributed the campaign to a threat actor group it tracks as TeamPCP.
According to the report, the malicious versions were 1.82.7 and 1.82.8, both pushed to the Python Package Index, or PyPI, which is the main repository many Python users rely on to install packages. LiteLLM acts as a unified gateway to more than 100 large language model providers, so a compromise of the library had the potential to expose credentials across multiple AI services at once.
Forcepoint said the attackers did not breach LiteLLM’s source code repository directly. Instead, they reached the package through its build pipeline after first compromising Trivy, an open-source vulnerability scanner used in LiteLLM’s continuous integration and continuous delivery workflow.
The company said TeamPCP previously took over Trivy by spoofing legitimate maintainer identities and pushing impersonated commits. It then used Trivy’s own automated release process to distribute backdoored binaries through GitHub Releases, Docker Hub and Amazon ECR.
When LiteLLM’s CI/CD job pulled the compromised Trivy build, the malicious binary scraped memory from the build runner and stole a PYPI_PUBLISH token. Forcepoint said the attackers used that token to publish their own LiteLLM releases directly to PyPI.
The two malicious LiteLLM versions used different ways to execute their payloads. Version 1.82.7 included a Base64-encoded payload inside proxy_server.py, which ran when the LiteLLM proxy started. Version 1.82.8 used a quieter method, dropping a litelllm_init.pth file into site-packages so the payload would run every time the Python interpreter started, even if LiteLLM was never imported.
Forcepoint said a normal pip install of the tainted release was enough to trigger the malware. Once active, the payload searched environment variables and configuration files for credentials tied to OpenAI, Anthropic and Microsoft Azure, along with Amazon Web Services, Google Cloud and Azure SDK credentials. It also looked for kubeconfig files and AWS credential files in users’ home directories.
The stolen data was encrypted using AES-256-CBC with a 32-byte session key derived through PBKDF2, then packed into a file named tpcp.tar.gz and sent out with curl to models.litellm.cloud, which Forcepoint described as an attacker-controlled lookalike domain.
The report says the malware also installed a persistence component called Sysmon.py. On first run it sleeps for 300 seconds, then checks checkmarx.zone every 50 minutes for new instructions, downloads any returned binary to /tmp/pglog and runs it as a background process.
Prashant Kumar, senior researcher at Forcepoint X-Labs, said the campaign is especially dangerous for AI and ML teams because LiteLLM sits in front of major AI providers. “A single compromise gave attackers simultaneous access to OpenAI, Anthropic and Azure credentials,” he wrote, adding that losing one library could mean losing access control across several connected AI providers at once.
The incident echoes a separate investigation by Datadog Security Labs in March, which linked the same TeamPCP campaign to a malicious PyPI package targeting Telnyx’s Python SDK. In a guest column for SiliconANGLE last week, Secure Code Warrior CTO Matias Madou argued that the Datadog case was the first successful weaponization of security and developer infrastructure with elevated access privileges. Forcepoint’s findings add another example of how attacker-controlled packages can be used to reach sensitive credentials through software supply chains.