Article

๐Ÿ“กrsssnyk-blog

How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM

On March 24, 2026, threat actor known as TeamPCP published backdoored versions of the litellm Python package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM's CI/CD pipeline.

ยทMar 24
Read Original
Sponsored
Ad
HomeTrendingBookmarksAgentSettings