TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign
ID: 96ea0a23-15e2-5c09-990e-c6725b41e33a
STIX ID: report--96ea0a23-15e2-5c09-990e-c6725b41e33a
Feed Name: DataBreaches.Net
Threat Score
### Executive summary A supply-chain campaign attributed to TeamPCP (aka Shellforce/CipherForce) compromised developer tooling between 19–24 March 2026, inserting a credential-stealing payload into Trivy, two Checkmarx editor plugins on OpenVSX, and poisoned LiteLLM packages on PyPI (one version installs a persistent backdoor that runs on Python startup), exposing passwords, cloud credentials (AWS/Azure/GCP) and crypto wallet data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
