science1 distinct publisher
LiteLLM 1.82.7 and 1.82.8 shipped an infostealer: rotate everything those machines touched
GitGuardian says the TeamPCP campaign poisoned two LiteLLM releases on PyPI to harvest SSH keys, cloud credentials and API tokens. Detection is the cheap part of this job.
Publishers:blog.gitguardian.com
Reality
- Evidence52
- Adoption27