← Back to feed
Threat Actors & CampaignsEmerging1 sourceMar 24, 2026 · 00:00via Datadog Security Labs

LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign

Brief

On March 24 and 27, 2026, malicious PyPI releases of LiteLLM and Telnyx were published as part of the TeamPCP supply chain campaign. We trace the full campaign from Trivy through npm, Checkmarx, and into PyPI.

Read more on Datadog Security Labs