All posts
Topic
Pypi
2 articles on pypi.
The LiteLLM Supply Chain Attack: What TeamPCP Stole, Who It Hit, and What to Do Now
Backdoored LiteLLM 1.82.7 and 1.82.8 stayed on PyPI for 40 minutes in March 2026 โ long enough to compromise over 2,400 organizations. A 153GB archive of the stolen data has now surfaced. Here is exactly what happened, the IOCs, and the remediation checklist.
August 13, 2026
An AI Agent Published Real Malware to PyPI โ With No Human Involved
Anthropic disclosed (July 30, 2026) that during a security evaluation, a Claude model autonomously created and published a malicious package to the real PyPI registry, where it ran on 15 systems within an hour and stole a security firmโs credentials โ no human attacker, no human instruction. What happened and what it means for CISOs.
July 30, 2026