Validated Containment Architectures are here. →Explore

Executive Summary

In March 2026, the TeamPCP cybercrime syndicate executed a sophisticated supply chain attack that compromised multiple open-source security tools including Trivy scanner, Checkmarx KICS, and LiteLLM AI gateway. The attackers stole publishing credentials from trusted projects and pushed poisoned versions through legitimate release channels across GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX ecosystems. This credential-chaining technique allowed them to compromise over 1,000 organizations globally, steal more than 500,000 credentials, and exfiltrate at least 300GB of sensitive data including CI/CD pipeline secrets and cloud access tokens.

This incident highlights the growing sophistication of supply chain attacks targeting the software development lifecycle, particularly as organizations increasingly rely on open-source components and automated CI/CD pipelines without proper security controls and credential management practices.

Why This Matters Now

Supply chain attacks are becoming the preferred attack vector for sophisticated threat actors, with a 742% increase in 2023. The TeamPCP incident demonstrates how attackers can weaponize trusted development tools to achieve massive scale compromises, making robust software supply chain security and zero trust principles critical for modern organizations.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

TeamPCP used a credential-chaining technique where they stole publishing credentials from one compromised project (Trivy) to attack the next (Checkmarx KICS), then used those credentials to compromise LiteLLM's build pipeline, creating a cascading supply chain attack.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF would likely have constrained TeamPCP's supply chain attack by limiting lateral movement between compromised CI/CD environments and reducing the blast radius across the 1,000+ affected organizations through workload segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero Trust fabric visibility would likely have detected anomalous authentication patterns and credential usage across the compromised security scanner infrastructure, potentially limiting the scope of initial credential harvesting activities.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Workload segmentation policies would likely have constrained the poisoned scanners' ability to access elevated privileges within victim CI/CD environments, reducing the scope of credential harvesting from segmented pipeline components.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely have constrained lateral movement between compromised CI/CD environments and external distribution platforms, reducing the attackers' ability to pivot across the 1,000+ organizations through segmented network paths.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility would likely have detected anomalous communication patterns between backdoored packages and external command infrastructure, constraining persistent channel establishment across the distributed CI/CD environments and AI workflow platforms.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress policy enforcement would likely have constrained the volume and scope of data exfiltration by limiting outbound data flows from compromised CI/CD environments, reducing the attackers' ability to extract the full 300+ GB dataset and 500,000+ credentials.

Impact (Mitigations)

Residual impact would likely be constrained to initially compromised credentials and published packages, with reduced organizational exposure scope due to segmentation limiting cross-environment credential propagation and constraining the overall blast radius.

Impact at a Glance

Affected Business Functions

  • Continuous Integration/Continuous Delivery (CI/CD) Pipelines
  • Software Development and Deployment
  • Cloud Infrastructure Management
  • Application Security Scanning
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Over 500,000 credentials compromised including CI/CD secrets, publishing tokens, and cloud credentials. At least 300 gigabytes of data exfiltrated from potentially 2,500+ organizations across multiple platforms including GitLab, GitHub Actions, Azure DevOps, Jenkins, and CircleCI. Exposed data includes corporate API keys, deployment credentials, and proprietary source code access tokens.

Recommended Actions

  • Implement Zero Trust segmentation to isolate CI/CD pipelines and prevent lateral movement between development and production environments
  • Deploy egress security controls with policy enforcement to detect and block unauthorized data exfiltration from CI/CD systems
  • Enable multicloud visibility and anomaly detection to identify suspicious automation patterns and repeated malformed requests in build pipelines
  • Establish encrypted traffic inspection capabilities to monitor east-west communications between development tools and external package repositories
  • Implement threat detection systems with baselining to identify covert tools and remote access patterns within CI/CD infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image