Related Threat Clusters
-
Supply Chain Attack Targets Checkmarx KICS Tool via Docker and VSCode Extensions
Hackers have compromised Docker images and VSCode extensions for the Checkmarx KICS analysis tool, which is used to identify security vulnerabilities in source code. The attack involved a trojanized KICS Docker image…
2 articles · Updated April 23, 2026 -
LiteLLM Supply Chain Attack Exposes Critical Credentials
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
3 articles · Updated June 12, 2026 -
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
JetBrains Cadence Breach: Exploitation of Unpatched TeamCity CVE-2026-63077
Between August 8 and August 24, 2026, attackers exploited CVE-2026-63077, a critical vulnerability in JetBrains TeamCity, to breach the JetBrains Cadence cloud compute service. The attackers accessed sensitive data,…
4 articles · Updated September 6, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise
AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…
30 articles · Updated April 1, 2026 -
Checkmarx Data Leak Linked to Supply-Chain Attack by TeamPCP
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
12 articles · Updated April 27, 2026 -
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts
A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access…
8 articles · Updated September 10, 2026 -
Megalodon Campaign Infects Over 5,500 GitHub Repositories with Malware
On May 18, 2026, an automated cyber campaign named Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attackers used forged identities and dummy accounts to inject malicious…
7 articles · Updated May 26, 2026 -
1K+ Cloud Environments Compromised in Trivy Supply Chain Attack
A supply chain attack targeting the Trivy open source scanner has infected over 1,000 cloud environments with secret-stealing malware. The attack, which occurred last week, has been attributed to a group called TeamPCP,…
3 articles · Updated March 24, 2026
Recent Intelligence Reports
- T1078.004 Valid Accounts: Cloud Accounts — attack.mitre.org · September 9, 2026
- AI Coding Tools Are Now Prime Targets for Threat Actors, Google Warns — Redpacketsecurity · September 9, 2026
- AI Coding Tools Now a Prime Target for Threat Actors, Google Warns — Infosecurity-Magazine · September 8, 2026
- Jetbrains Told Everyone To Patch It Didnt Patch Itself — thenewstack.io · September 6, 2026
- Megalodon Mass Github Repo Backdooring Ci Workflows — safedep.io · July 19, 2026
- Hunting Leaked PyPI Tokens: 62 Live, 125 Packages Exposed — Blog.Gitguardian · June 24, 2026
- LiteLLM supply-chain incident — www.trendmicro.com · June 12, 2026
- Aikido Supports Docker Hardened Images with VEX — Aikido.Dev · June 11, 2026