FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

TeamPCP Supply-Chain Compromise of Trivy, Checkmarx KICS, and LiteLLM

In March 2026, the TeamPCP cybercrime syndicate executed a targeted software supply-chain compromise against the Trivy security scanner, Checkmarx KICS (Infrastructure as Code scanner), and LiteLLM AI gateway. By injecting malicious code directly into these high-trust open-source repositories, the actors deployed automated credential-harvesting payloads. The campaign compromised over 500,000 credentials across more than 1,000 global organizations. Following an international investigation by the Australian Federal Police (AFP) and the FBI, suspects Louis Michael Gaebler and Ruben Ian Thomson were arrested in August 2026. This incident highlights the critical risk of "security tool weaponization" within DevSecOps and AI infrastructure pipelines.


LINK COPIED TO CLIPBOARD