When Trusted Packages Turn Hostile: Cascading Supply Chain Attacks
TeamPCP hid a credential stealer in a WAV file inside telnyx 4.87.1 on PyPI, using tokens stolen from litellm three days earlier. Why the cascade evades review.
2 articles with this tag.
TeamPCP hid a credential stealer in a WAV file inside telnyx 4.87.1 on PyPI, using tokens stolen from litellm three days earlier. Why the cascade evades review.
TeamPCP pushed a credential stealer into litellm 1.82.7 and 1.82.8 on PyPI via a compromised Trivy action. What it did, and why AI skills are next.