The AI Agent That Opened the PyPI Backdoor

ByteVanguard featured card, "AI Found the Door," tracing an AI-agent supply-chain kill chain from recon to a backdoored LiteLLM on PyPI

AI Security

In late February 2026, no human sat at the keyboard for the opening move. An autonomous bot called hackerbot-claw hunted CI/CD misconfigurations across open-source repositories and stole the GitHub token that — five days and three hops later — put a backdoored LiteLLM on PyPI. The software supply chain now has a machine at the front of its kill chain.

ByteVanguard• June 2026• Supply Chain

Bottom Line An AI agent did not push malware to PyPI — a human crew, TeamPCP, did that. But the bot is why their job scaled: hackerbot-claw autonomously found the weak workflow and stole the credential that opened the cascade. The lesson isn’t that AI wrote ransomware. It’s that autonomous initial access is now a fixed part of the supply-chain threat model — and the controls that blunt it are unglamorous and already on the shelf. Pin to hashes. Rotate completely. Treat your scanners as attack surface.

The five-day cascade

The LiteLLM backdoor was the visible end of a chain that began weeks earlier and somewhere else entirely. Reconstructed from vendor and researcher reporting, it ran like this.

  • LATE FEB
    hackerbot-claw — an AI-powered autonomous bot later attributed to the TeamPCP cluster — opened innocuous-looking pull requests against CI/CD workflows at Microsoft, Datadog, and Aqua Security, abusing a pull_request_target (“pwn request”) misconfiguration to steal GitHub personal access tokens, including the token for Aqua’s automation account.
  • MAR 1 · THE MISS
    Aqua disclosed the intrusion and rotated credentials. Researchers later assessed the rotation was incomplete — residual access survived it. This is the moment the whole thing could have ended and didn’t.
  • MAR 19
    Using that residual access, TeamPCP force-pushed malicious commits to 76 of 77 version tags of the Trivy scanner’s GitHub Action, disguising them with the original authors’ metadata and timestamps. Any pipeline pinned to a tag silently began running attacker code.
  • MAR 23
    With credentials harvested from Trivy-infected pipelines, the crew pivoted into Checkmarx’s KICS Action and pushed two trojanized VS Code extensions to the OpenVSX registry.
  • MAR 24 · LITELLM
    LiteLLM’s own pipeline ran the poisoned Trivy action during routine scanning. The stealer harvested the maintainer’s PyPI publish token, and TeamPCP used it to publish litellm 1.82.7 and 1.82.8 — the backdoored releases.
  • MAR 27
    Three days later, the Telnyx Python SDK (CVE-2026-33634) fell to the same campaign.

Where the AI agent actually fits

It is tempting to read this as a machine that autonomously breached PyPI. It didn’t. The package push, the tag rewriting, and the post-compromise extortion were human-run TeamPCP. The AI agent’s job was narrower and, for defenders, more unsettling: it ran the front of the kill chain.

The kill chain, by operator
01 · RECON
Hunt CI/CD misconfigs across high-value repos
hackerbot-claw · AI
02 · ACCESS
Steal the GitHub token from Aqua’s pipeline
hackerbot-claw · AI
03 · SPREAD
Rewrite Trivy’s tags, pivot to Checkmarx
TeamPCP · human
04 · PAYLOAD
Publish the backdoored LiteLLM to PyPI
TeamPCP · human
↓   AUTONOMOUS FRONT, HUMAN FINISH   ↓
AI: recon + initial access Human: propagation + payload

Hackerbot-claw, self-described as powered by a frontier model, did the part that used to bottleneck on skilled human time — hunting for a specific, exploitable CI/CD misconfiguration across a set of high-value repositories and exfiltrating the token once it found one. That is reconnaissance and initial access, executed autonomously and in parallel across targets. The humans took it from there.

The threat-model shift is simple to state and hard to absorb: initial access no longer scales with attacker headcount. One operator can point an agent at thousands of repositories and collect whatever opens. The attribution of hackerbot-claw to TeamPCP is a researcher assessment rather than a confirmed identity — but the operational pattern, an autonomous bot in front of human operators, is what matters for defense, and it is not going back in the box.

Why LiteLLM was the prize

Of everything TeamPCP touched, LiteLLM was the crown jewel, and the reason is architectural. LiteLLM is a universal model gateway: a single Python interface that routes API calls to OpenAI, Anthropic, Google Gemini, AWS Bedrock, and more than a hundred other providers. Organizations deploy it as an internal AI proxy and configure it with credentials for every provider they use. That convenience is exactly the exposure — a compromised LiteLLM instance doesn’t leak one API key, it leaks the entire AI provider stack from a single place.

~97M
LiteLLM monthly PyPI downloads
33,688
Internet-facing deployments (Hunt.io)
~47,000
Downloads during the exposure window
100+
Providers a single instance can hold keys for

The 1.82.8 payload made that reach worse. Rather than waiting to be imported, it dropped a .pth file into Python’s site-packages directory — a mechanism that executes on every interpreter startup: pip, a one-line python invocation, an IDE’s language server. Any Python process on the box, not just LiteLLM, would trigger it. Once running, the stealer swept environment variables, SSH keys, cloud and Kubernetes credentials, Docker configs, and CI/CD secrets; encrypted the haul with AES-256 under an RSA-4096 key; and exfiltrated it to a hardcoded endpoint, tagged with a campaign-specific HTTP header. Then it installed a systemd-based foothold to persist.

Your scanner is your attack surface

The most important sentence in this whole incident is one defenders keep skating past: the attack rode in on a security tool. Trivy is a vulnerability scanner — software you add to a pipeline specifically to make it safer. Teams investigating the LiteLLM breach found no direct attack on LiteLLM’s infrastructure at all. They found the cost of trusting a scanner that had already been quietly subverted upstream.

CI/CD security tooling runs with broad, implicit trust: access to the build environment, to secrets, to publish credentials. It is rarely vetted with the rigor applied to application dependencies, because it carries the word “security” in its description. This campaign is the counter-argument. A scanner, a linter, or a test framework in your pipeline is a dependency like any other — and a more privileged one than most.

Two ordinary failures, one cascade

Strip away the novelty and the chain turned on two failures that have nothing to do with AI.

The first is mutable references. GitHub Actions resolve version tags at runtime, and a tag can be silently rewritten by anyone with write access. Every pipeline that pinned the Trivy action to a floating tag inherited attacker code the instant the tags were rewritten — no change to their own workflow files required.

The second is incomplete rotation. Aqua rotated credentials after disclosure, but the rotation missed something, and that residual access is precisely what let TeamPCP return eighteen days later to rewrite the tags. A partial rotation is not a rotation; it is a delay.

“The bot didn’t write the ransomware. It found the door — at machine speed, across every repository at once. That’s the part that doesn’t scale back down.”

What to do this week

None of the fixes are new, and that is the point. The campaign exploited ordinary pipeline hygiene gaps; ordinary pipeline hygiene closes them.

01 · Pin

Pin Actions to commit SHAs, not tags

Replace floating tag references with immutable commit SHAs. A tag can be rewritten; a SHA cannot. Automate the pinning and keep it current with Dependabot or Renovate.

02 · Verify

Hash-pin your PyPI dependencies

Use pip’s require-hashes mode or a hash-verified lockfile so an installed package must match a previously reviewed artifact. It won’t stop a version that was malicious on day one, so pair it with supply-chain monitoring.

03 · Distrust tools

Vet security tooling like any dependency

Scanners, linters, and test frameworks run with high privilege inside your pipeline. Subject them to the same provenance and integrity checks you apply to application libraries, and scope the secrets they can reach.

04 · Lock the gateway

Treat AI-proxy keys like cloud root keys

LiteLLM, Portkey, OpenRouter, and internal proxies pool every provider credential in one layer. Scope keys per model and use case where the provider allows it, and rotate on a schedule regardless of suspected compromise.

If you were exposed Any host or CI job that ran the Trivy GitHub Action, the Checkmarx KICS Action, or any LiteLLM PyPI package between March 19 and 27 should be treated as a full-credential exposure — not just a package-presence problem. Rotate every reachable LLM, cloud, and CI secret; audit site-packages for the malicious .pth file or any other unexpected .pth entries; and review egress logs for the campaign’s known exfiltration endpoints. Assume the credentials were taken and work backward, rather than waiting for an indicator to confirm it.

Sourcing: The timeline, the attribution of hackerbot-claw to TeamPCP, and the AI-gateway exposure analysis are drawn from the Cloud Security Alliance’s TeamPCP research note, with corroborating technical detail from Snyk, Datadog Security Labs, and Sonatype. The hackerbot-claw–TeamPCP link is a researcher assessment, not a confirmed identity. Accounts of the PyPI exposure window differ: LiteLLM’s advisory and the CSA note put it near 40 minutes, while several trackers reported roughly three hours; the ~47,000-download figure comes from the latter. The 300 GB exfiltrated from 500,000+ systems reported elsewhere is a campaign-wide figure across all four compromised ecosystems, not LiteLLM alone. Identifiers: PYSEC-2026-2 and Sonatype sonatype-2026-001357 (LiteLLM); CVE-2026-33634 (Telnyx).

References

1
Cloud Security Alliance · Research Note
TeamPCP: Trojanized Security Tools Backdoor AI Infrastructure — campaign timeline, attribution, and AI-gateway risk
csa.org
2
Snyk
How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM — CI/CD chain and payload mechanics
snyk.io
3
Datadog Security Labs
LiteLLM and Telnyx Compromised on PyPI: Tracing the TeamPCP Campaign — indicators and payload behavior
datadoghq.com
4
Sonatype
Compromised litellm PyPI Package Delivers Multi-Stage Credential Stealer — payload analysis (sonatype-2026-001357 / PYSEC-2026-2)
sonatype.com
5
LiteLLM · Official
Security Update: Suspected Supply Chain Incident — March 2026 — affected versions and exposure window
litellm.ai
6
Help Net Security
Prompt injection still drives most agentic AI security failures in production — agentic-attack framing
helpnetsecurity.com

Support independent security analysis

If you find ByteVanguard useful, you can support the site and help keep the analysis independent.

Support the analysis
Intelligence over headlines. Signal over noise.

Stay Connected

Report Intelligence
© 2026 ByteVanguard. Built for security professionals.