Credential‑Stealing Malware in LiteLLM Supply Chain Attack

Executive Summary A severe malware incident (no formal CVE yet, but tracked as a high‑risk supply chain compromise) was disclosed affecting the widely used Python package LiteLLM (PyPI). Attackers from the TeamPCP threat group trojanized LiteLLM by publishing malicious versions 1.82.7 and 1.82.8, allowing them to harvest credentials and deploy backdoors when the package is […]

The post Credential‑Stealing Malware in LiteLLM Supply Chain Attack appeared first on Orca Security.

原始链接: https://orca.security/resources/blog/litellm-supply-chain-attack-malware/
侵权请联系站方: [email protected]

相关推荐

换一批