TeamPCP Supply Chain Campaign: When the Security Scanner Became a Weapon Against AI Infrastructure
Executive Summary
On March 24, 2026, threat group TeamPCP successfully pushed two backdoored versions of the Python library LiteLLM (v1.82.7 and v1.82.8) to PyPI — a package registry serving over 95 m
blog.fiscybersec.com15 min read