CVE
CVE-2026-33634
Trivy ecosystem supply chain briefly compromised
Exploitation IoCs 8
Domain models[.]litellm[.]cloud
Domain scan[.]aquasecurtiy[.]org
Filename litellm_init.pth
GitHub Repo docs-tpcp
GitHub Repo tpcp-docs
IP 45[.]148[.]10[.]212
Package [email protected]
Package [email protected]
MITRE ATT&CK TTPs 8
T1005 T1027 T1059.001 T1059.003 T1071.001 T1195.002 T1555 T1566
Data from Local System
Collection
Obfuscated Files or Information
Defense Evasion
PowerShell
Execution
Windows Command Shell
Execution
Web Protocols
Command And Control
Compromise Software Supply Chain
Initial Access
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Source Articles
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Malicious versions 1.82.7 and 1.82.8 of the open-source LiteLLM package were uploaded to PyPI on March 24, 2026, and remained available for approximately 40 minutes before being quarantined. These compromised releases contained a credential-stealing payload that collected environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database passwords, exfiltrating them to the domain models.litellm[.]cloud. The incident is part of the broader TeamPCP supply-chain campaign, linked to the earlier compromise of Aqua Security's Trivy scanner, which allowed attackers to gain access to PyPI publishing tokens. The attack potentially exposed over 2,100 organizations, with stolen data including sensitive CI/CD secrets that remain exploitable if not rotated.
hacker-news Aug 12, 2026
10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions
In March 2026, the threat actor TeamPCP compromised 76 version tags of the aquasecurity/trivy-action GitHub Action by injecting a credential stealer, exploiting elevated privileges to harvest secrets from memory and exfiltrate them to a malicious domain. The same actor targeted other platforms including PyPI packages litellm and telnyx, and previously compromised the Checkmarx KICS GitHub Action using similar tactics. These supply chain attacks highlight a broader trend of targeting CI/CD pipelines to steal credentials and cloud tokens. The attacks leveraged typosquatted domains and memory scraping techniques, underscoring the need for layered defenses in GitHub Actions environments.
step-security Jul 2, 2026