critical AI Issue

LiteLLM/Trivy/KICS Supply Chain Compromise (TeamPCP)

Severitycritical
Statusopen
DateMarch 24, 2026
AffectsLiteLLM (3.4M daily downloads), Trivy, KICS, Telnyx
Sourcesemgrep.dev

Details

TeamPCP compromised four major open-source projects in rapid succession (March 19-27). Malicious versions harvest AWS/GCP/Azure tokens, SSH keys, and Kubernetes credentials. Three-stage payload with persistent backdoor.