Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
vendor-distribution-compromisebuild-pipeline-compromisepackage-repository-poisoningleaked-secret-api-key

TeamPCP Supply-Chain Attacks Poisoned Trivy, KICS, LiteLLM, Telnyx, and Bitwarden

Updated 15d agoFirst seen Apr 11, 202615 sources

A broad software supply-chain campaign attributed to TeamPCP compromised trusted developer and security tools, beginning with a poisoned Trivy GitHub Action after attackers allegedly stole a personal access token via a misconfigured pull_request_target workflow. Researchers said malicious commits were pushed to most Trivy action tags, allowing the attackers to steal CI/CD secrets, cloud credentials, SSH keys, Kubernetes configuration, and other sensitive data from downstream users. The campaign then spread through stolen credentials to additional projects, including Checkmarx KICS, LiteLLM versions 1.82.7 and 1.82.8 on PyPI, the Telnyx SDK, and later Bitwarden CLI, with malware exfiltrating data to attacker-controlled infrastructure such as checkmarx[.]zone and models[.]litellm[.]cloud. Reporting also tied the operation to hundreds of compromised systems and large-scale theft of .env files and secrets from cloud, AI, payment, database, and messaging environments.

The fallout expanded beyond package poisoning into downstream intrusions and data leaks. Checkmarx confirmed that data later leaked by LAPSUS$ came from its private GitHub repository and said the initial access was likely enabled by credentials exposed in the Trivy-related compromise; researchers also linked the broader campaign to Bitwarden through shared malware and command-and-control patterns. Malicious KICS Docker images, GitHub Actions, and editor extensions were reported to steal credentials and scan results, while Bitwarden’s CI/CD workflow was allegedly abused to expose an npm token and publish a tainted @bitwarden/cli release. Security researchers and vendors warned that the campaign shows how attackers are increasingly targeting open-source maintainers and security tooling as high-leverage entry points, with reported ties to extortion and ransomware groups including LAPSUS$ and Vect raising the risk that stolen access will be resold or used for follow-on attacks.

Share:
TeamPCP Supply-Chain Attacks Poisoned Trivy, KICS, LiteLLM, Telnyx, and Bitwarden
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

16 events from the most recent confirmed update back to the earliest known activity.

16 EVENTS
May 20, 20261mo ago

GitHub confirms TeamPCP breach of internal source control

On May 20, 2026, GitHub confirmed that TeamPCP breached its internal source control after a poisoned VS Code extension was installed by an employee, leading to the theft of about 3,800 internal repositories. GitHub said it found no evidence that customer data was affected.

TeamPCP and Cyber Supply Chain Attacks - Flare | Identity First Threat Intelligence | Unmatched Visibility into Cybercrime
Apr 29, 20262mo ago

Ars reports Bitwarden affected and TeamPCP linked to Lapsu$

On April 29, 2026, reporting said the broader TeamPCP campaign also affected Bitwarden and suggested TeamPCP likely sold Checkmarx access to Lapsu$. The article linked the incidents through shared command-and-control infrastructure and malware characteristics associated with the Trivy breach.

Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica
Apr 28, 20262mo ago

Analysis ties Checkmarx KICS compromise to Bitwarden CLI poisoning

An April 28, 2026 analysis described how the compromised Checkmarx KICS scanner was allegedly used inside Bitwarden's CI/CD workflow to steal GitHub and Azure credentials, expose an npm token, and publish a malicious @bitwarden/cli version 2026.4.0. The report characterized the malware as worm-like, using stolen GitHub and npm credentials to propagate through workflows and packages.

Bitwarden CLI 침해로 이어진 Checkmarx KICS 공급망 공격 - 보안 도구를 역이용한 공급망 공격

Checkmarx links leaked GitHub data to TeamPCP-enabled access

On April 28, 2026, Checkmarx confirmed that data leaked by LAPSUS$ came from its private GitHub repository and said initial access was likely enabled by credentials exposed in the March 23 Trivy-related supply-chain attack. The company said the leaked dataset was about 96GB and that customer information was not believed to be included.

Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data
Apr 22, 20262mo ago

Checkmarx KICS Docker images and extensions poisoned

On April 22, 2026, attackers published malicious Docker images and VSCode/Open VSX extensions for the Checkmarx KICS scanner. Checkmarx said the artifacts were designed to steal credentials, keys, tokens, and configuration files.

Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data
Apr 11, 20263mo ago

The Register reports dual March open-source supply-chain attacks

On April 11, 2026, reporting connected the TeamPCP Trivy-centered campaign with a separate Axios npm compromise attributed by Google to North Korean-linked UNC1069. The Axios incident reportedly followed social engineering of maintainer Jason Saayman and malicious releases published for about three hours.

Two different attackers poisoned popular open source tools • The Register
Apr 2, 20263mo ago

Researchers detail TeamPCP shell arsenal across March campaign

On April 2, 2026, researchers published technical analysis of TeamPCP's shell-based tooling used against Trivy, Checkmarx KICS, LiteLLM, and Telnyx. The report documented credential theft, Kubernetes-aware payload delivery, encrypted exfiltration, and GitHub fallback mechanisms.

Inside TeamPCP’s Shell Arsenal - THE RAVEN FILE
Apr 1, 20263mo ago

Investigation reports 900+ compromised systems in ongoing operation

A security investigation described on April 1, 2026 reported an exposed server tied to an ongoing exploitation and data-collection operation with more than 900 confirmed compromised systems. The operation allegedly harvested tens of thousands of .env files and used AI-assisted tooling to optimize attacks.

Mercor Confirms LiteLLM Supply Chain Attack | CelerFlow posted on the topic | LinkedIn
Mar 27, 20263mo ago

Akamai reports TeamPCP campaign and Vect partnership claim

On March 27, 2026, Akamai published research tying the Trivy, Checkmarx KICS, and LiteLLM compromises into a single TeamPCP supply-chain campaign. The report also noted a claimed partnership between TeamPCP and the ransomware group Vect, raising concern about downstream monetization of stolen access.

The Telnyx SDK on PyPI Compromise and the 2026 TeamPCP Supply Chain Attacks | Akamai
Mar 26, 20263mo ago

CISA adds CVE-2026-33634 to the KEV catalog

A March 26, 2026 campaign update said CISA added CVE-2026-33634 to its Known Exploited Vulnerabilities catalog, confirming active exploitation and triggering remediation deadlines for federal agencies.

TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available

PyPI yanks malicious LiteLLM releases and BerriAI freezes releases

By March 26, 2026, PyPI had lifted quarantine on LiteLLM after yanking malicious versions 1.82.7 and 1.82.8, while BerriAI froze new releases and engaged Mandiant for forensic analysis. Guidance said all affected installations should be treated as compromised.

TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available
Mar 24, 20263mo ago

Malicious LiteLLM 1.82.7 and 1.82.8 released to PyPI

On March 24, 2026, attackers used credentials harvested from LiteLLM's CI/CD pipeline to publish malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI. The packages reused the same stealer seen in the Trivy incident and exfiltrated data to attacker-controlled infrastructure.

The Telnyx SDK on PyPI Compromise and the 2026 TeamPCP Supply Chain Attacks | Akamai
Mar 23, 20263mo ago

All 91 Checkmarx ast-github-action tags found overwritten

An update reported that all 91 published tags of Checkmarx's ast-github-action, from v0.1-alpha through v2.3.32, were overwritten with individually crafted malicious commits on March 23, 2026. The malicious composite action ran a credential-stealing setup.sh before invoking the legitimate action.

TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available

Attackers use stolen credentials to poison Checkmarx KICS

On March 23, 2026, the campaign expanded when attackers used credentials stolen through the Trivy compromise to publish malicious updates affecting Checkmarx KICS. Reporting later said the compromise included poisoned GitHub Action tags and malicious code in KICS-related distribution channels.

The Telnyx SDK on PyPI Compromise and the 2026 TeamPCP Supply Chain Attacks | Akamai
Mar 19, 20263mo ago

TeamPCP compromises Trivy GitHub Action tags

On March 19, 2026, attackers attributed to TeamPCP used a stolen personal access token obtained via a misconfigured pull_request_target workflow to push malicious commits to 76 of 77 Trivy GitHub Action version tags. The poisoned action exposed secrets and credentials from organizations whose CI/CD pipelines executed it.

The Telnyx SDK on PyPI Compromise and the 2026 TeamPCP Supply Chain Attacks | Akamai
Dec 14, 20256mo ago

TeamPCP's earliest traced shell tooling dates to December 2025

Analysis of TeamPCP's shell arsenal found the earliest traced shell artifact dated December 14, 2025, indicating the group had built propagation and proxy infrastructure months before the March 2026 campaign.

Inside TeamPCP’s Shell Arsenal - THE RAVEN FILE
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

67 LINKEDOpen in app
Vulnerabilities
1 linked
Affected products
15 linked
LitellmVisual Studio CodeLitellmTelnyxTrivyTrivyClaude CodeGithubBitwardenAmazon Web ServicesKubernetesDockerBunClaudeAnthropic
Organizations
28 linked
CheckmarxSocketBitwardenAqua SecurityWizGoogleBerriAITelnyxAnthropicGitHubSysdigMercorLitellmCisco SystemsThe RegisterPython Software FoundationBleepingComputerAikido SecuritySANS InstituteOpen VSXDatadogMend.ioOpenaiDockerEndor LabsFlareCSO OnlineBlueRock
Breaches
7 linked
CHECKMARX-2023-03BITWARDEN-2023-03CHECKMARX-2026-03LITELLM-2026-03TRIVY-2026-03CHECKMARXKICS-2026-03BITWARDEN-2026-04
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

TeamPCP Supply-Chain Attacks Poisoned Trivy, KICS, LiteLLM, Telnyx, and Bitwarden | Mallory