Skip to main content
SkillSafe
Apps Skills Models Docs Blog Pricing Dashboard
Signed in as

Dashboard API Keys Billing Credits Settings
Esc
↑↓ navigate ↵ open ⇧↵ view all tab source esc close View all skills →
Home / Blog / #pypi

#pypi

2 articles with this tag.

Security Mar 28, 2026 12 min read

When Trusted Packages Turn Hostile: Cascading Supply Chain Attacks

TeamPCP hid a credential stealer in a WAV file inside telnyx 4.87.1 on PyPI, using tokens stolen from litellm three days earlier. Why the cascade evades review.

Security Mar 25, 2026 17 min read

LiteLLM's PyPI Backdoor: What It Means for the AI Skill Supply Chain

TeamPCP pushed a credential stealer into litellm 1.82.7 and 1.82.8 on PyPI via a compromised Trivy action. What it did, and why AI skills are next.

SkillSafe

The secured registry for AI skills.

Get Started

Quickstart Claude Code Cursor Windsurf Codex Turn a skill into an app

Product

Apps Skills Models Rankings Demos Trending Scan Pricing Docs

Security

Overview MCP Security Why SkillSafe

Company

Blog Changelog GitHub Privacy Terms Support
© 2026 SkillSafe
SOC 2 Certified HIPAA Compliant Every Shared Skill Scanned

Sign in to SkillSafe

Don't have an account?

or

By signing in, you agree to our Terms and Privacy Policy.

Create a SkillSafe Account

Already have an account?

or

By signing up, you agree to our Terms and Privacy Policy.

Verify your email

We sent a code to

Reset your password

Enter reset code

We sent a code to

Send Feedback
0 / 2000