Tag: TeamPCP

  • Weaponising the Guards: Deconstructing TeamPCP’s Cascading CI/CD Supply Chain Campaign

    In late March 2026, the financially motivated cybercriminal group TeamPCP executed a five-day cascading supply chain operation that compromised three widely deployed developer security tools: Aqua Security’s Trivy, Checkmarx’s KICS, and BerriAI’s LiteLLM. By exploiting a pull_request_target misconfiguration and intercepting incomplete credential rotations, TeamPCP hijacked mutable GitHub version tags (@v2) and PyPI publishing tokens. The compromised tools—running with elevated permissions in thousands of enterprise CI/CD pipelines—were turned into automated credential-harvesting engines, exfiltrating over 300GB of secrets across more than 500,000 environments.

    (more…)