Incident Critical npm PyPI openvsix TeamPCP Part II: Backdooring the AI Credentials Vault TeamPCP's endgame: LiteLLM's PyPI wheel backdoored post-build, .pth system-wide persistence, and why AI gateways are a new class of supply chain target. Daniel Malvaceda · Apr 1, 2026 · 27 min read