Malware e strumenti · Supply chain
TeamPCP ha sfruttato credenziali rubate per compromettere i repository Trivy di Aqua Security e le GitHub Actions associate. Gli attori hanno force-pushed 76 tag su trivy-action e tutti i tag di setup-trivy e hanno pubblicato un binario Trivy infetto.
11 fonti · 25 mar
SecurityWeek
From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$.
originaleMicrosoft Security Blog
Guidance for detecting, investigating, and defending against the Trivy supply chain compromise | Microsoft Security Blog
This analysis walks through the Trivy supply‑chain compromise, attacker techniques, and concrete steps security teams can take to detect and defend against similar attacks.
originaleThe Hacker News
TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise
Malicious LiteLLM 1.82.7–1.82.8 via Trivy compromise deploys backdoor and steals credentials, enabling Kubernetes-wide persistence and lateral spread.
originalePart of the PlainSec briefing for 2026-03-25
Every edition of this story: Compromesso GitHub Actions di Trivy Espone Segreti CI/CD