Fetching from the wire…
Public story · 2026-03-21 · source-backed
TeamPCP force-pushed malicious code into 75 of 76 version tags in aquasecurity/trivy-action, injecting a credential stealer into the widely-used vulnerability scanning GitHub Action. Version 0.69.4 runs both the legitimate scanner and malware that exfiltrates environment variables, API tokens, cloud credentials, and SSH keys to scan.aquasecurtiy[.]org (typosquat). Any CI/CD pipeline that ran a poisoned tag should be treated as fully compromised. Rotate all secrets immediately.
Each link below shares sources, entities, or timing with this story.
Threat actors hijacked 75 of 76 Trivy release tags and the trivy-action GitHub Action, injecting a credential stealer that dumps Runner.Worker memory and exfiltrates SSH, cloud, and Kubernetes secrets encrypted with AES-256+RSA-4096. The same TeamPCP group has launched Caniste...
Hudson Rock got hold of the archive and counted it. 433,909 files. 118,829 CI runner dumps traced to 2,488 corporate domains. AWS keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys belonging to NVIDIA, Volkswagen, Micr...
Every Python process on your machine just became a potential credential exfiltration endpoint if you installed the wrong version of LiteLLM today. LiteLLM versions 1.82.7 and 1.82.8, published to PyPI on March 24, contained a malicious .pth file that executes automatically on...
A security scanner. The tool your team trusts to find vulnerabilities. That was the entry point. The TeamPCP campaign compromised Aqua Security's Trivy scanner (a GitHub Action used in CI/CD pipelines), then used that foothold to backdoor LiteLLM's CI/CD pipeline, then pivoted...
Two AI toolchain CVEs hit CISA's Known Exploited Vulnerabilities catalog this week, and the attack chain connecting them is the kind of thing that should change how you think about supply chain trust. CVE-2026-33017: Langflow, the popular agent workflow builder, has an unauthe...
The token was rotated. It was never revoked. That gap was about twenty days wide, and it was enough. CloudSEK disclosed that Team PCP compromised LiteLLM PyPI versions 1.82.7 and 1.82.8 by taking over the Trivy security scanner inside LiteLLM's build process. The mechanism: a...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.