logo

Supply chain attack: Security scanner compromise leads to widespread infostealer and ransomware pivot

ID: 0615537c-a513-5048-a349-2af7713f573e

STIX ID: report--0615537c-a513-5048-a349-2af7713f573e

Feed Name: ThreatLocker Blog

Threat Score
92/100

Date Published: 2026-04-07

Date Updated: 2026-05-01

...
...

A coordinated supply-chain campaign by threat actor "TeamPCP" exploited a CI privilege escalation in the aquasecurity/trivy GitHub repository to inject malicious Trivy artifacts that harvested secrets and credentials; stolen credentials were then used to hijack PyPI and npm accounts (notably LiteLLM), distributing infostealer payloads (proxy_server.py, litellm_init.pth, sysmon.py) that establish persistence, exfiltrate vast ranges of secrets to typosquatted domains, and enable follow-on ransomware activity; the report includes technical analysis, IOCs (hashes, domains, commands, IPs), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.