logo

TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign

ID: 96ea0a23-15e2-5c09-990e-c6725b41e33a

STIX ID: report--96ea0a23-15e2-5c09-990e-c6725b41e33a

Feed Name: DataBreaches.Net

Threat Score
88/100

Date Published: 2026-03-25

Date Updated: 2026-04-19

Author: Dissent

...
...

### Executive summary A supply-chain campaign attributed to TeamPCP (aka Shellforce/CipherForce) compromised developer tooling between 19–24 March 2026, inserting a credential-stealing payload into Trivy, two Checkmarx editor plugins on OpenVSX, and poisoned LiteLLM packages on PyPI (one version installs a persistent backdoor that runs on Python startup), exposing passwords, cloud credentials (AWS/Azure/GCP) and crypto wallet data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.