logo

TeamPCP Supply Chain Attack Campaign Targets Trivy, Checkmarx (KICS), and LiteLLM (Potential Downstream Impact to Additional Projects)

ID: 722e484c-d9c0-5062-8799-8be805fbc7cf

STIX ID: report--722e484c-d9c0-5062-8799-8be805fbc7cf

Feed Name: Arctic Wolf Blog

Threat Score
88/100

Date Published: 2026-03-25

Date Updated: 2026-06-11

...
...

### Executive summary TeamPCP conducted a coordinated supply-chain campaign by stealing CI/CD secrets and signing credentials to compromise Trivy, Checkmarx GitHub Actions, and LiteLLM PyPI packages, distributing credential-stealing backdoors and worm-like propagation mechanisms that risk widespread downstream compromise; vendors have removed malicious artifacts and Arctic Wolf recommends reverting to safe versions, rotating credentials, monitoring SBOMs and build logs, and deploying detection agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.