Voices
TeamPCP Supply Chain Campaign Spreads: Trivy (March 19) → KICS GitHub Action → LiteLLM (March 24) in Five Days
The TeamPCP threat actor group executed a cascading supply chain attack across developer tools in just five days — first compromising Trivy (a popular security scanner) on March 19, then pivoting to KICS GitHub Actions and Checkmarx, and finally using stolen CI/CD credentials to publish credential-stealing code to LiteLLM on PyPI. ReversingLabs and Wiz documented the campaign, which exploits the trust relationship between security tools and the packages they scan, creating a novel attack pattern where compromising a scanner provides access to everything it scans.
Source
↳ Follow the thread