TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign
ID: 35f44d45-f5c0-51af-b7ca-61e200953959
STIX ID: report--35f44d45-f5c0-51af-b7ca-61e200953959
Feed Name: HackRead
Threat Score
**Executive summary:** Between 19–24 March 2026, an ongoing supply‑chain campaign attributed to 'TeamPCP' infected Trivy, Checkmarx tools/plugins and LiteLLM with a credential‑stealing malware that harvests cloud keys, Kubernetes tokens and Solana wallets, persists via a background service, and was distributed through poisoned updates and malicious packages; the report urges immediate rotation of keys, use of clean tool versions, and pinning packages by SHA to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
