A coordinated supply chain attack attributed to threat actor TeamPCP has compromised multiple developer tools: Checkmarx's KICS GitHub Action and two VS Code plugins were poisoned on March 23, following a similar attack on Aqua Security's Trivy scanner. The campaign also spread to PyPI, infecting LiteLLM packages (versions

5m read timeFrom darkreading.com
Post cover image
Table of contents
A Broadening Supply Chain AttackAttackers Are After Developer SecretsThe TeamPCP Cyber Threat Set to Grow

Sort: