Threat actor group TeamPCP published two malicious versions (1.82.7 and 1.82.8) of the popular LiteLLM Python package to PyPI, using maintainer credentials obtained through an earlier compromise of the Trivy vulnerability scanner. The trojanized package harvested SSH keys, cloud credentials, Kubernetes secrets, database passwords, CI/CD tokens, and cryptocurrency wallet data from systems that installed it. LiteLLM serves as a gateway used by CrewAI, DSPy, Microsoft GraphRAG, and many other AI agent frameworks; researchers estimate the backdoored versions reached over 2,500 companies and roughly 434,000 CI/CD pipelines before removal.