Executive Summary
Between February and June 2026, the cybercriminal group TeamPCP executed a series of supply chain attacks, compromising over 1,000 open-source software packages. By infiltrating widely used tools such as Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK, TeamPCP exploited vulnerabilities in CI/CD pipelines and AI development tools to inject malicious code, leading to the exfiltration of sensitive data and credentials. This campaign underscored the critical weaknesses in the software supply chain, particularly the reliance on unverified code dependencies and the lack of rigorous security checks in automated deployment systems. The incident highlights the urgent need for organizations to reassess their software development practices, emphasizing the importance of verifying the integrity of open-source components and implementing robust security measures within CI/CD pipelines. As supply chain attacks become more prevalent, the industry must prioritize security to prevent similar large-scale compromises in the future.
Why This Matters Now
The TeamPCP attacks reveal critical vulnerabilities in the software supply chain, emphasizing the need for organizations to implement rigorous security measures in their development processes to prevent future large-scale compromises.
Attack Path Analysis
TeamPCP initiated the attack by compromising widely-used open-source software packages, injecting malicious code to gain initial access. They escalated privileges by exploiting stolen credentials and misconfigurations within CI/CD pipelines. The attackers moved laterally across cloud environments by leveraging compromised Kubernetes credentials to access additional resources. They established command and control channels using encrypted communications to maintain persistent access. Sensitive data, including API keys and proprietary information, was exfiltrated to external servers. The impact included significant data breaches, operational disruptions, and erosion of trust in software supply chains.
Kill Chain Progression
Initial Compromise
Description
TeamPCP compromised open-source software packages by injecting malicious code, leading to unauthorized access when these packages were integrated into development environments.
Related CVEs
CVE-2026-33634
CVSS 9.4A vulnerability in Trivy's CI/CD infrastructure allowed unauthorized code injection, leading to the distribution of malicious releases.
Affected Products:
Aqua Security Trivy – 0.69.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Compromise Software Dependencies and Development Tools
Compromise Software Supply Chain
Valid Accounts
Unsecured Credentials
Command and Scripting Interpreter
Obfuscated Files or Information
Impair Defenses
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
TeamPCP's supply chain attacks directly compromise software repositories, CI/CD pipelines, and open-source dependencies critical to development workflows and operations.
Information Technology/IT
Automated deployment systems and cloud infrastructure credentials targeted by TeamPCP expose IT organizations to lateral movement and privilege escalation risks.
Financial Services
High-value targets with strict compliance requirements face significant exposure through compromised software dependencies and automated systems lacking proper validation controls.
Health Care / Life Sciences
HIPAA compliance frameworks and critical healthcare systems vulnerable to supply chain compromise through infected open-source packages and development tools.
Sources
- How software development’s speed obsession enabled TeamPCP’s chaos crusadehttps://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/Verified
- TeamPCP Compromised LiteLLM in AI Supply Chain Attackhttps://www.esecurityplanet.com/threats/teampcp-compromised-litellm-in-ai-supply-chain-attack/Verified
- Telnyx Targeted in Growing TeamPCP Supply Chain Attackhttps://www.securityweek.com/telnyx-targeted-in-growing-teampcp-supply-chain-attack/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit compromised software packages would likely be constrained, reducing the risk of unauthorized access to development environments.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges within the development environment would likely be constrained, reducing the risk of unauthorized access to sensitive resources.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally across cloud environments would likely be constrained, reducing the risk of unauthorized access to additional resources.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be constrained, reducing the risk of persistent access to compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data to external servers would likely be constrained, reducing the risk of data breaches.
The overall impact of the attack would likely be reduced, limiting data breaches, operational disruptions, and erosion of trust in software supply chains.
Impact at a Glance
Affected Business Functions
- Software Development
- Continuous Integration/Continuous Deployment (CI/CD) Pipelines
- Cloud Infrastructure Management
Estimated downtime: 7 days
Estimated loss: $500,000
Compromise of developer credentials, cloud service tokens, and access to internal source code repositories.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within cloud environments.
- • Enhance East-West Traffic Security to monitor and control internal traffic, detecting unauthorized movements.
- • Deploy Multicloud Visibility & Control solutions to gain comprehensive insights across cloud platforms and detect anomalies.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and enforce outbound traffic policies.
- • Establish Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious activities promptly.



