TeamPCP Compromises Trivy/LiteLLM Supply Chain

UV Cyber pdf 2026-03-31T00:00:00

Abstract

The recent TeamPCP campaign demonstrates how attackers are targeting trusted software supply chain components—specifically CI/CD and release mechanisms linked to the Trivy ecosystem—to compromise downstream packages like LiteLLM. By abusing legitimate development and distribution channels, the threat actor delivers malicious code, harvests credentials, and can pivot from build environments into broader enterprise infrastructure, highlighting a shift from isolated package tampering to broad trust‑mechanism exploitation.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 9.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD