ended3월 25일· 1 sources

How the TeamPCP attack exploited CI/CD pipelines and trusted releases to release infected Trivy and LiteLLM packages

TeamPCP 공격이 CI/CD 파이프라인과 신뢰된 릴리스 체계를 악용하여 감염된 Trivy 및 LiteLLM 패키지를 배포한 방법

Why it matters

The TeamPCP attack exploited CI/CD pipelines to push infected packages through trusted release channels. Notable targets included Aquasec's entire GitHub account, including the Trivy repository, and the LiteLLM Python package, which were used to distribute infostealers.

1
Sources
+0
24h
Growth
180d
Active
TeamPCPCI/CDTrivyLiteLLMAquasecinfostealer

Sources

Related Issues