logo

TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign

ID: 35f44d45-f5c0-51af-b7ca-61e200953959

STIX ID: report--35f44d45-f5c0-51af-b7ca-61e200953959

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive summary:** Between 19–24 March 2026, an ongoing supply‑chain campaign attributed to 'TeamPCP' infected Trivy, Checkmarx tools/plugins and LiteLLM with a credential‑stealing malware that harvests cloud keys, Kubernetes tokens and Solana wallets, persists via a background service, and was distributed through poisoned updates and malicious packages; the report urges immediate rotation of keys, use of clean tool versions, and pinning packages by SHA to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.