Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

The threat group TeamPCP injected credential-stealing malware into LiteLLM versions 1.82.7 and 1.82.8, a widely deployed AI/LLM orchestration library downloaded approximately 3.4 million times daily, with estimated exposure across up to 500,000 devices. The malware targets cloud provider credentials (AWS, GCP, Azure), SSH keys, Kubernetes secrets, and cryptocurrency wallets, creating direct risk of cloud account takeover, data exfiltration, and infrastructure compromise. This attack is part of a documented, multi-target campaign by TeamPCP that has previously poisoned security tools including Aqua Security Trivy and Checkmarx KICS, indicating a deliberate effort to target DevOps and AI/ML pipelines at the tooling layer.

Author

Tech Jacks Solutions