CVE

CVE-2026-33634

Trivy ecosystem supply chain briefly compromised

Exploitation IoCs 8

Domain models[.]litellm[.]cloud
Domain scan[.]aquasecurtiy[.]org
Filename litellm_init.pth
GitHub Repo docs-tpcp
GitHub Repo tpcp-docs
IP 45[.]148[.]10[.]212

MITRE ATT&CK TTPs 8

Source Articles

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Malicious versions 1.82.7 and 1.82.8 of the open-source LiteLLM package were uploaded to PyPI on March 24, 2026, and remained available for approximately 40 minutes before being quarantined. These compromised releases contained a credential-stealing payload that collected environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database passwords, exfiltrating them to the domain models.litellm[.]cloud. The incident is part of the broader TeamPCP supply-chain campaign, linked to the earlier compromise of Aqua Security's Trivy scanner, which allowed attackers to gain access to PyPI publishing tokens. The attack potentially exposed over 2,100 organizations, with stolen data including sensitive CI/CD secrets that remain exploitable if not rotated.
hacker-news Aug 12, 2026
10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions
In March 2026, the threat actor TeamPCP compromised 76 version tags of the aquasecurity/trivy-action GitHub Action by injecting a credential stealer, exploiting elevated privileges to harvest secrets from memory and exfiltrate them to a malicious domain. The same actor targeted other platforms including PyPI packages litellm and telnyx, and previously compromised the Checkmarx KICS GitHub Action using similar tactics. These supply chain attacks highlight a broader trend of targeting CI/CD pipelines to steal credentials and cloud tokens. The attacks leveraged typosquatted domains and memory scraping techniques, underscoring the need for layered defenses in GitHub Actions environments.
step-security Jul 2, 2026