The TeamPCP software supply-chain campaign compromised CI/CD tooling and packages including Trivy, KICS, LiteLLM, Telnyx, CanisterWorm, and more than 66 npm packages. Malicious code deployed TeamPCP Cloud Stealer to collect GitHub, cloud-provider, SSH, and package-manager credentials; on GitHub-hosted Linux runners, it dumped Runner.Worker process memory to extract secrets. Stolen credentials were reportedly reused to move between victims and expand the compromise chain.
The LiteLLM intrusion reportedly added Kubernetes lateral-movement features, Python .pth persistence, and exfiltration to attacker-created GitHub repositories. Organizations using affected build pipelines should rotate potentially exposed credentials, review CI/CD logs and runner activity for memory-dumping behavior and unauthorized repository access, and investigate package versions and build artifacts for tampering. Canary credentials placed in runner files, environment variables, and memory can provide early alerts when credential-stealing malware accesses or uses decoy secrets.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Two malicious versions of the Telnyx PyPI package were reportedly published. The campaign assessment linked this compromise to credentials likely obtained from the previously compromised LiteLLM environment.
Two malicious versions of the LiteLLM PyPI package were reportedly published. The compromised payload included credential theft and Kubernetes-focused lateral-movement capabilities.
GitHub Actions and OpenVSX extensions associated with Checkmarx's KICS scanner were reportedly compromised.
Credentials stolen in the Trivy compromise were reportedly used to compromise more than 66 npm packages through the self-propagating CanisterWorm.
Several GitHub Actions associated with Aqua Security's Trivy scanner were reportedly compromised. Malicious Trivy versions were also published to Docker Hub as part of the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.