
In late February 2026, no human sat at the keyboard for the opening move. An autonomous bot called hackerbot-claw hunted CI/CD misconfigurations across open-source repositories and stole the GitHub token that — five days and three hops later — put a backdoored LiteLLM on PyPI. The software supply chain now has a machine at the front of its kill chain.
The LiteLLM backdoor was the visible end of a chain that began weeks earlier and somewhere else entirely. Reconstructed from vendor and researcher reporting, it ran like this.
It is tempting to read this as a machine that autonomously breached PyPI. It didn’t. The package push, the tag rewriting, and the post-compromise extortion were human-run TeamPCP. The AI agent’s job was narrower and, for defenders, more unsettling: it ran the front of the kill chain.
Hackerbot-claw, self-described as powered by a frontier model, did the part that used to bottleneck on skilled human time — hunting for a specific, exploitable CI/CD misconfiguration across a set of high-value repositories and exfiltrating the token once it found one. That is reconnaissance and initial access, executed autonomously and in parallel across targets. The humans took it from there.
The threat-model shift is simple to state and hard to absorb: initial access no longer scales with attacker headcount. One operator can point an agent at thousands of repositories and collect whatever opens. The attribution of hackerbot-claw to TeamPCP is a researcher assessment rather than a confirmed identity — but the operational pattern, an autonomous bot in front of human operators, is what matters for defense, and it is not going back in the box.
Of everything TeamPCP touched, LiteLLM was the crown jewel, and the reason is architectural. LiteLLM is a universal model gateway: a single Python interface that routes API calls to OpenAI, Anthropic, Google Gemini, AWS Bedrock, and more than a hundred other providers. Organizations deploy it as an internal AI proxy and configure it with credentials for every provider they use. That convenience is exactly the exposure — a compromised LiteLLM instance doesn’t leak one API key, it leaks the entire AI provider stack from a single place.
The 1.82.8 payload made that reach worse. Rather than waiting to be imported, it dropped a .pth file into Python’s site-packages directory — a mechanism that executes on every interpreter startup: pip, a one-line python invocation, an IDE’s language server. Any Python process on the box, not just LiteLLM, would trigger it. Once running, the stealer swept environment variables, SSH keys, cloud and Kubernetes credentials, Docker configs, and CI/CD secrets; encrypted the haul with AES-256 under an RSA-4096 key; and exfiltrated it to a hardcoded endpoint, tagged with a campaign-specific HTTP header. Then it installed a systemd-based foothold to persist.
The most important sentence in this whole incident is one defenders keep skating past: the attack rode in on a security tool. Trivy is a vulnerability scanner — software you add to a pipeline specifically to make it safer. Teams investigating the LiteLLM breach found no direct attack on LiteLLM’s infrastructure at all. They found the cost of trusting a scanner that had already been quietly subverted upstream.
CI/CD security tooling runs with broad, implicit trust: access to the build environment, to secrets, to publish credentials. It is rarely vetted with the rigor applied to application dependencies, because it carries the word “security” in its description. This campaign is the counter-argument. A scanner, a linter, or a test framework in your pipeline is a dependency like any other — and a more privileged one than most.
Strip away the novelty and the chain turned on two failures that have nothing to do with AI.
The first is mutable references. GitHub Actions resolve version tags at runtime, and a tag can be silently rewritten by anyone with write access. Every pipeline that pinned the Trivy action to a floating tag inherited attacker code the instant the tags were rewritten — no change to their own workflow files required.
The second is incomplete rotation. Aqua rotated credentials after disclosure, but the rotation missed something, and that residual access is precisely what let TeamPCP return eighteen days later to rewrite the tags. A partial rotation is not a rotation; it is a delay.
“The bot didn’t write the ransomware. It found the door — at machine speed, across every repository at once. That’s the part that doesn’t scale back down.”
None of the fixes are new, and that is the point. The campaign exploited ordinary pipeline hygiene gaps; ordinary pipeline hygiene closes them.
Replace floating tag references with immutable commit SHAs. A tag can be rewritten; a SHA cannot. Automate the pinning and keep it current with Dependabot or Renovate.
Use pip’s require-hashes mode or a hash-verified lockfile so an installed package must match a previously reviewed artifact. It won’t stop a version that was malicious on day one, so pair it with supply-chain monitoring.
Scanners, linters, and test frameworks run with high privilege inside your pipeline. Subject them to the same provenance and integrity checks you apply to application libraries, and scope the secrets they can reach.
LiteLLM, Portkey, OpenRouter, and internal proxies pool every provider credential in one layer. Scope keys per model and use case where the provider allows it, and rotate on a schedule regardless of suspected compromise.
Sourcing: The timeline, the attribution of hackerbot-claw to TeamPCP, and the AI-gateway exposure analysis are drawn from the Cloud Security Alliance’s TeamPCP research note, with corroborating technical detail from Snyk, Datadog Security Labs, and Sonatype. The hackerbot-claw–TeamPCP link is a researcher assessment, not a confirmed identity. Accounts of the PyPI exposure window differ: LiteLLM’s advisory and the CSA note put it near 40 minutes, while several trackers reported roughly three hours; the ~47,000-download figure comes from the latter. The 300 GB exfiltrated from 500,000+ systems reported elsewhere is a campaign-wide figure across all four compromised ecosystems, not LiteLLM alone. Identifiers: PYSEC-2026-2 and Sonatype sonatype-2026-001357 (LiteLLM); CVE-2026-33634 (Telnyx).
If you find ByteVanguard useful, you can support the site and help keep the analysis independent.
Support the analysis