Supply chain attack: Security scanner compromise leads to widespread infostealer and ransomware pivot
ID: 0615537c-a513-5048-a349-2af7713f573e
STIX ID: report--0615537c-a513-5048-a349-2af7713f573e
Feed Name: ThreatLocker Blog
A coordinated supply-chain campaign by threat actor "TeamPCP" exploited a CI privilege escalation in the aquasecurity/trivy GitHub repository to inject malicious Trivy artifacts that harvested secrets and credentials; stolen credentials were then used to hijack PyPI and npm accounts (notably LiteLLM), distributing infostealer payloads (proxy_server.py, litellm_init.pth, sysmon.py) that establish persistence, exfiltrate vast ranges of secrets to typosquatted domains, and enable follow-on ransomware activity; the report includes technical analysis, IOCs (hashes, domains, commands, IPs), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
