A broad software supply-chain campaign attributed to TeamPCP compromised trusted developer and security tools, beginning with a poisoned Trivy GitHub Action after attackers allegedly stole a personal access token via a misconfigured pull_request_target workflow. Researchers said malicious commits were pushed to most Trivy action tags, allowing the attackers to steal CI/CD secrets, cloud credentials, SSH keys, Kubernetes configuration, and other sensitive data from downstream users. The campaign then spread through stolen credentials to additional projects, including Checkmarx KICS, LiteLLM versions 1.82.7 and 1.82.8 on PyPI, the Telnyx SDK, and later Bitwarden CLI, with malware exfiltrating data to attacker-controlled infrastructure such as checkmarx[.]zone and models[.]litellm[.]cloud. Reporting also tied the operation to hundreds of compromised systems and large-scale theft of .env files and secrets from cloud, AI, payment, database, and messaging environments.
The fallout expanded beyond package poisoning into downstream intrusions and data leaks. Checkmarx confirmed that data later leaked by LAPSUS$ came from its private GitHub repository and said the initial access was likely enabled by credentials exposed in the Trivy-related compromise; researchers also linked the broader campaign to Bitwarden through shared malware and command-and-control patterns. Malicious KICS Docker images, GitHub Actions, and editor extensions were reported to steal credentials and scan results, while Bitwarden’s CI/CD workflow was allegedly abused to expose an npm token and publish a tainted @bitwarden/cli release. Security researchers and vendors warned that the campaign shows how attackers are increasingly targeting open-source maintainers and security tooling as high-leverage entry points, with reported ties to extortion and ransomware groups including LAPSUS$ and Vect raising the risk that stolen access will be resold or used for follow-on attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
On July 2, 2026, the FBI issued a FLASH alert attributing large-scale software supply-chain compromises to TeamPCP, saying the group trojanized tools including Trivy, KICS, LiteLLM, and the Telnyx Python SDK to steal cloud credentials and access CI/CD and cloud environments. The alert also described npm account hijacking via stale recovery email domains and published indicators of compromise and mitigation guidance.
On May 20, 2026, GitHub confirmed that TeamPCP breached its internal source control after a poisoned VS Code extension was installed by an employee, leading to the theft of about 3,800 internal repositories. GitHub said it found no evidence that customer data was affected.
On April 29, 2026, reporting said the broader TeamPCP campaign also affected Bitwarden and suggested TeamPCP likely sold Checkmarx access to Lapsu$. The article linked the incidents through shared command-and-control infrastructure and malware characteristics associated with the Trivy breach.
An April 28, 2026 analysis described how the compromised Checkmarx KICS scanner was allegedly used inside Bitwarden's CI/CD workflow to steal GitHub and Azure credentials, expose an npm token, and publish a malicious @bitwarden/cli version 2026.4.0. The report characterized the malware as worm-like, using stolen GitHub and npm credentials to propagate through workflows and packages.
On April 28, 2026, Checkmarx confirmed that data leaked by LAPSUS$ came from its private GitHub repository and said initial access was likely enabled by credentials exposed in the March 23 Trivy-related supply-chain attack. The company said the leaked dataset was about 96GB and that customer information was not believed to be included.
On April 22, 2026, attackers published malicious Docker images and VSCode/Open VSX extensions for the Checkmarx KICS scanner. Checkmarx said the artifacts were designed to steal credentials, keys, tokens, and configuration files.
On April 11, 2026, reporting connected the TeamPCP Trivy-centered campaign with a separate Axios npm compromise attributed by Google to North Korean-linked UNC1069. The Axios incident reportedly followed social engineering of maintainer Jason Saayman and malicious releases published for about three hours.
On April 2, 2026, researchers published technical analysis of TeamPCP's shell-based tooling used against Trivy, Checkmarx KICS, LiteLLM, and Telnyx. The report documented credential theft, Kubernetes-aware payload delivery, encrypted exfiltration, and GitHub fallback mechanisms.
A security investigation described on April 1, 2026 reported an exposed server tied to an ongoing exploitation and data-collection operation with more than 900 confirmed compromised systems. The operation allegedly harvested tens of thousands of .env files and used AI-assisted tooling to optimize attacks.
On March 27, 2026, Akamai published research tying the Trivy, Checkmarx KICS, and LiteLLM compromises into a single TeamPCP supply-chain campaign. The report also noted a claimed partnership between TeamPCP and the ransomware group Vect, raising concern about downstream monetization of stolen access.
A March 26, 2026 campaign update said CISA added CVE-2026-33634 to its Known Exploited Vulnerabilities catalog, confirming active exploitation and triggering remediation deadlines for federal agencies.
By March 26, 2026, PyPI had lifted quarantine on LiteLLM after yanking malicious versions 1.82.7 and 1.82.8, while BerriAI froze new releases and engaged Mandiant for forensic analysis. Guidance said all affected installations should be treated as compromised.
On March 24, 2026, attackers used credentials harvested from LiteLLM's CI/CD pipeline to publish malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI. The packages reused the same stealer seen in the Trivy incident and exfiltrated data to attacker-controlled infrastructure.
An update reported that all 91 published tags of Checkmarx's ast-github-action, from v0.1-alpha through v2.3.32, were overwritten with individually crafted malicious commits on March 23, 2026. The malicious composite action ran a credential-stealing setup.sh before invoking the legitimate action.
On March 23, 2026, the campaign expanded when attackers used credentials stolen through the Trivy compromise to publish malicious updates affecting Checkmarx KICS. Reporting later said the compromise included poisoned GitHub Action tags and malicious code in KICS-related distribution channels.
On March 19, 2026, attackers attributed to TeamPCP used a stolen personal access token obtained via a misconfigured pull_request_target workflow to push malicious commits to 76 of 77 Trivy GitHub Action version tags. The poisoned action exposed secrets and credentials from organizations whose CI/CD pipelines executed it.
Analysis of TeamPCP's shell arsenal found the earliest traced shell artifact dated December 14, 2025, indicating the group had built propagation and proxy infrastructure months before the March 2026 campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesecurityaffairs.com
Open sourceflare.io
Open sourcearstechnica.com
Open sourceakamai.com
Open sourceisc.sans.edu
Open sourceriskledger.com
Open sourcelabs.cloudsecurityalliance.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.