惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

SiliconANGLE

Agentic transformation needs context engineering - SiliconANGLE Quantum computing: Hybrid systems will drive future - SiliconANGLE CircuitHub raises $28M to scale electronics production in days rather than months - SiliconANGLE Post-quantum encryption for secure data architectures - SiliconANGLE Enterprise agentic AI in focus for Google Cloud - SiliconANGLE NanoCo raises $12M to accelerate NanoClaw, a secure, enterprise-grade agentic AI assistant for every office worker - SiliconANGLE Forward launches Predict to verify network changes before they reach production - SiliconANGLE 1Password extends OpenAI collaboration with Codex MCP server for just-in-time credential access - SiliconANGLE WisdomAI's new analytics agents go beyond insights, automating business work through autonomous action - SiliconANGLE Informatica expands agentic AI strategy with headless data services and unified agent governance - SiliconANGLE Riverbed adds agentic AI, session replay and AI observability to Aternity platform - SiliconANGLE Exclusive: Juicebox autonomous recruiting agents help source candidates proactively - SiliconANGLE DataDome debuts Priority Protect, a virtual waiting room built for AI shopping agents - SiliconANGLE Tribal AI lands $10M in seed funding to bring metadata-native agents to the enterprise - SiliconANGLE Tenable adds multistep reasoning and MCP support to Hexa AI agent - SiliconANGLE Terra Security unifies web, AI and network testing under one agentic platform - SiliconANGLE Armada raises $230M at $2B valuation to build portable AI data centers - SiliconANGLE Google Flow adds agentic brainstorming, more precise editing tools and sharing features - SiliconANGLE Google to embed AI shopping features in multiple services with Universal Cart - SiliconANGLE Google shows off first intelligent specs running Android XR - SiliconANGLE Meta shifts 7,000 employees into four new AI units ahead of mass layoffs - SiliconANGLE Becoming AI-native is no longer a path to success — it’s an operational prerequisite Google, Blackstone launch AI infrastructure joint venture - SiliconANGLE AI infrastructure, data and courage inform Dell's next move - SiliconANGLE Five takeaways from Michael Dell's keynote at Dell Technologies World 2026 - SiliconANGLE Google whips up more AI in Workspace with new voice, image editing and inbox tools - SiliconANGLE Google reimagines search with AI agents and generative interfaces - SiliconANGLE Google accelerates agent-native software development with expanded Antigravity platform - SiliconANGLE Google expands AI-powered app discovery and Android development tools at I/O - SiliconANGLE Google unveils Gemini Spark, an always-on AI agent for daily digital tasks - SiliconANGLE Google targets AI agents and video generation with Gemini 3.5 Flash and Omni - SiliconANGLE Dell overhauls data center portfolio with AI-focused storage, servers and cyber resilience tools - SiliconANGLE Multi-agent orchestration and the crawl-walk-run path to AI - SiliconANGLE Sola Security launches Lumina to cut enterprise security alert noise with contextual AI - SiliconANGLE LaunchDarkly launches runtime control layer for the agentic AI era - SiliconANGLE Darwinium pushes mobile fraud detection beyond the login moment - SiliconANGLE Everpure pitches storage as the last line of cyber defense in the AI era - SiliconANGLE Torq acquires AI security startup Jit to add context graphs to its security operations center platform - SiliconANGLE Voker raises $2.2M to help teams understand how AI agents perform in the wild - SiliconANGLE Assured autonomy and the bridge to AI production - SiliconANGLE Enterprise AI startup Unframe raises $50M after booking $100M in contract value in year one - SiliconANGLE Fully autonomous AI demands a new enterprise anchor - SiliconANGLE AI factory momentum at Dell reaches an inflection point - SiliconANGLE Decart raises $300M for its AI optimization software, world models - SiliconANGLE Federal jury rules against Elon Musk in closely watched OpenAI trial - SiliconANGLE Sigma Computing seals $80M funding round as it pivots towards 'agentic analytics' - SiliconANGLE Sigma Computing seals $80M funding round as it pivots toward 'agentic analytics' - SiliconANGLE Mid-market AI adoption demands data readiness - SiliconANGLE Eric Schmidt booed during commencement speech over AI remarks - SiliconANGLE Enterprise AI integration scales with agentic platforms - SiliconANGLE Intelligent digital workers and the modern attack surface - SiliconANGLE AI governance gap splotlighted in the agentic workforce - SiliconANGLE Dell targets enterprise AI execution gap with local agentic AI systems and integrated AI infrastructure - SiliconANGLE Red Hat OpenShift Service on AWS cuts procurement cost - SiliconANGLE Trusted execution layer in focus with Ansible automation - SiliconANGLE Building domain-specific AI in ecosystem partnerships - SiliconANGLE Redis debuts the much-needed memory layer for enterprise AI agents - SiliconANGLE Multiplayer AI startup Dust raises $40M to help enterprises move beyond isolated AI assistants - SiliconANGLE Enterprise infrastructure driven by Dell partnerships - SiliconANGLE Eval engineering: The missing piece of agentic AI governance - SiliconANGLE OpenAI previews personal finance features in ChatGPT Pro - SiliconANGLE GridCare raises $64M to speed up AI data center projects - SiliconANGLE Contact center AI transformation drives better CX - SiliconANGLE Telco cloud modernization accelerates at Red Hat - SiliconANGLE Agent risk management mission-critical for an AI workforce - SiliconANGLE AI resilience: Insights from Veeam's next evolution - SiliconANGLE The software supply chain is the new ground zero for enterprise cyber risk. Don't get caught short - SiliconANGLE Cerebras' monster IPO, Cisco's big quarter, and the AI factory's real impact - SiliconANGLE SaaS applications transform in the headless enterprise - SiliconANGLE Boomi Companion plans to agentic engineering pay off - SiliconANGLE Veeam claims the missing data and AI trust layer - SiliconANGLE Dataiku launches governed AI workflow builder inside Snowflake - SiliconANGLE OpenAI reportedly mulls taking Apple to court over ChatGPT's Siri integration - SiliconANGLE OpenAI brings Codex to mobile devices, adds more customization features - SiliconANGLE Applied Materials boosts its outlook as AI chipmakers scramble to add more production capacity - SiliconANGLE AI training data provider Wirestock raises $23M in funding - SiliconANGLE A $10T bet: Coupa leverages data to build its case for AI and autonomous spend management - SiliconANGLE PwC expands Anthropic alliance, will train 30,000 staff on Claude - SiliconANGLE Autodesk taps Permiso Security to monitor AI agents across its cloud and workforce - SiliconANGLE Red Hat outlines sovereign AI strategy amid growing regulation and control concerns - SiliconANGLE Figma stock jumps as first-quarter revenue surges 46% on AI monetization traction - SiliconANGLE Agent governance in focus for the Boomi-AWS alliance - SiliconANGLE Graphon reels in $8.3M for its persistent relational memory platform - SiliconANGLE Liquid data and shift to headless enterprise architecture - SiliconANGLE Data intelligence powers Dell’s AI factory evolution - SiliconANGLE The dual-threat landscape and evolution of digital workers - SiliconANGLE AI trust infrastructure defines Veeams next evolution - SiliconANGLE Anthropic announces ‘programmatic credit pool’ as agentic tool use rises - SiliconANGLE Building a durable AI ecosystem through open innovation - SiliconANGLE ZenBusiness launches AI-ready infrastructure for business formation and compliance - SiliconANGLE Service software drives AI strategy at Freshworks Refresh - SiliconANGLE How the WNBA-AWS data play can turn engagement into fans - SiliconANGLE Open source AI trust and inference at Red Hat - SiliconANGLE SecurityScorecard acquires internet scanning startup Driftnet to bolster third-party risk platform - SiliconANGLE Fleet launches autonomous endpoint management platform to counter AI-accelerated exploits - SiliconANGLE Saile raises $2.2M to reduce paperwork for healthcare staffing - SiliconANGLE Data center cooling tech startup Iceotope aims to scale after raising $26M - SiliconANGLE Open enterprise hybrid cloud with Microsoft - SiliconANGLE Enterprise AI architecture evolves for the agentic AI era - SiliconANGLE Okta extends AI agent security to Amazon Bedrock, opens platform to rival identity providers - SiliconANGLE
Forcepoint details TeamPCP supply chain attack that turned LiteLLM into a credential stealer - SiliconANGLE
Duncan Riley · 2026-05-18 · via SiliconANGLE

Forcepoint details TeamPCP supply chain attack that turned LiteLLM into a credential stealer

A new report out today from cybersecurity company Forcepoint LLC’s X-Labs research team details a supply chain attack that compromised LiteLLM, a widely used open-source Python library that serves as a unified gateway to more than 100 large language model providers, turning two malicious releases of the package into a credential-stealing tool aimed at cloud and artificial intelligence environments.

The attack, attributed to a threat actor group tracked as TeamPCP, pushed malicious versions 1.82.7 and 1.82.8 of LiteLLM to the Python Package Index. The compromise did not stem from a breach of LiteLLM’s source code repository. Instead, the attackers reached the package through its build pipeline after first poisoning Trivy, a popular open-source vulnerability scanner used in LiteLLM’s continuous integration and deployment workflow.

According to Forcepoint, TeamPCP had previously taken over Trivy by spoofing legitimate maintainer identities and pushing impersonated commits, then triggered the project’s automated release pipeline to distribute backdoored binaries through GitHub Releases, Docker Hub and Amazon ECR. When LiteLLM’s continuous integration/continuous delivery job pulled the compromised Trivy build, the malicious binary scraped the runner’s memory and exfiltrated a PYPI_PUBLISH token. The attackers used the stolen credentials to publish their own LiteLLM releases directly to PyPI.

The two malicious versions used different injection techniques. Version 1.82.7 carried a Base64-encoded payload embedded inside proxy_server.py that executed when the LiteLLM proxy started. Version 1.82.8 took a stealthier approach, dropping a litelllm_init.pth file into site-packages so the payload ran at Python interpreter startup on every subsequent process, regardless of whether LiteLLM was ever explicitly imported. A standard “pip install” of the tainted release was enough to activate it.

Once active, the payload scanned environment variables and configuration files for cloud and AI service credentials. Targets included OpenAI Group PBC, Anthropic PBC and Microsoft Azure API keys, along with Amazon Web Services Inc., Google Cloud and Azure SDK credentials. The malware also pulled local kubeconfig files and AWS credential files from user home directories.

The collected data was encrypted with a 32-byte AES-256-CBC session key derived through PBKDF2, packed into a file named tpcp.tar.gz and exfiltrated over curl to a domain at models.litellm.cloud, an attacker-controlled lookalike of the legitimate LiteLLM domain.

Forcepoint says that the malware also installed a polling backdoor called Sysmon.py for persistence. The script sleeps for 300 seconds on first run, then checks a remote URL at checkmarx.zone every 50 minutes for fresh instructions, downloading any returned binary to /tmp/pglog and executing it as a background process.

“What makes this campaign uniquely dangerous for AI and ML teams is the nature of the target,” Prashant Kumar, senior researcher at Forcepoint X-Labs, wrote in the report. “LiteLLM functions as a unified gateway to major AI providers, meaning a single compromise gave attackers simultaneous access to OpenAI, Anthropic and Azure credentials. Losing one library effectively means losing access control across multiple connected AI providers at once.”

The compromise echoes a parallel investigation by Datadog Inc.’s Security Labs, which in March linked the same TeamPCP campaign to a second malicious PyPI publication targeting Telnyx Inc.’s Python software development kit.

Writing in a guest column for SiliconANGLE last week, Secure Code Warrior Ltd. Chief Technology Officer Matias Madou argued that the attack detailed by Datadog marked the first successful weaponization of security and developer infrastructure with elevated access privileges. AI middleware such as LiteLLM should now be treated as critical infrastructure in enterprise governance frameworks, he wrote.

Image: SiliconANGLE/Ideogram

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About SiliconANGLE Media

SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.