TeamPCP looted LiteLLM in 46 minutes. A patient attacker uses the same proxy position for far more. Three surfaces your AI security posture isn't covering.
TeamPCP's endgame: LiteLLM's PyPI wheel backdoored post-build, .pth system-wide persistence, and why AI gateways are a new class of supply chain target.