Topic: pypi security

  • LiteLLM PyPI packages hijacked in TeamPCP supply chain attacks

    LiteLLM PyPI packages hijacked in TeamPCP supply chain attacks

    A coordinated software supply chain attack by the group TeamPCP compromised the popular LiteLLM library on March 24, uploading malicious versions to PyPI that contained credential stealers and malware droppers. The attack targeted a critical point in the AI application stack, risking exposure of ...

    Read More »
  • Python Foundation Rejects US Security Grant

    Python Foundation Rejects US Security Grant

    The Python Software Foundation rejected a $1.5 million U.S. government grant because the terms would have prohibited its diversity, equity, and inclusion (DEI) initiatives, conflicting with its core mission. The grant was intended to fund the development of proactive security tools for the Python...

    Read More »