www.securityweek.com 8/14/2026, 12:07:20 PM · external

TeamPCP compromises LiteLLM through poisoned Trivy scanner

TeamPCP compromises LiteLLM through poisoned Trivy scanner
CyberSIXT Evidence Panel
Primary Source hudsonrock.com
Threat Actor

THE LiteLLM supply chain attack, attributed to TeamPCP, affected over 2,500 organizations, primarily due to a compromised version of Aqua Security’s Trivy scanner. The attack propagated through multiple packages and repositories, exploiting a malicious payload that harvested sensitive data, including tokens and API keys. Most compromised organizations were victims of the Trivy incident, and the attack duration spanned just over five days, from March 19 to March 24, 2026.

The stolen credentials are now being brokered on platforms like Telegram. The malware specifically targeted JWT and authentication tokens, and was noted for its persistence on already-infected hosts.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline