Security1 distinct publisher2 min readPublished
TeamPCP's method is to spend the secrets it steals from one project's build pipelines on breaking into the next, which makes CI/CD credentials the asset worth defending and a third party's list the way most victims found out.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Do the division on the exfiltration. 78,330 secrets across 2,186 organizations is about 36 secrets per victim [1], and over five days that is roughly 15,700 secrets a day [2] taken from around 437 fresh organizations a day [3]. That rate is a property of the runner rather than the attacker: secrets arrive in a job as environment variables that any step can read [14], so one malicious step reads the whole envelope.
The Trivy GitHub Action shows how the step gets in. StepSecurity reports the credential stealer landed in 76 of the 77 published version tags [6], which is 98.7 percent of the references an operator could have pinned [4]. Tags are mutable, and an attacker with control of the project can silently repoint them [16], so pinning by version was not a control. The same technique worked on the Checkmarx KICS action days later [7], and a WAV steganography stealer went into the telnyx PyPI package [8].
Platform choice did not help. Azure DevOps appears in more than 230 of the victim organizations [12], about one in ten of the set [5], and it is the platform usually left out of supply chain discussion.
Provenance matters for the rest of it. The platform breakdown is StepSecurity's decoding of CloudSEK's published dataset, not an independent tally [19], and StepSecurity says it discovered or was among the first to publicly report many of the 2026 compromises [11] while selling controls for this exact failure mode. Calling the LiteLLM compromise the largest supply chain attack on AI infrastructure to date is CloudSEK's characterization [9]. StepSecurity's further claim, that work once needing nation-state resources can now be run by one person with an AI coding agent, rests on artifacts its own team analyzed, including self-spreading worms aimed at AI coding agents and timelines compressed from months to days [18]. The CloudSEK victim list does not speak to that part.
What the list does establish is a detection gap with a named cause. Most of the 2,186 organizations learned their build systems were leaking when the data went public [4], and runners ship with open outbound network access [15], so 36 secrets per organization left the pipeline without tripping anything those organizations had instrumented. The credentials themselves are the reason this reads as a campaign and not a run of unrelated incidents: source control credentials and cloud keys landed in hundreds of victims [17], and TeamPCP's stated playbook is to spend them on the next trusted component [1].
Ranked by verification strength, evidence, and original report placement.
In March 2026, 78,330 secrets were exfiltrated from the CI/CD pipelines of 2,186 organizations in five days, which StepSecurity describes as one of the largest credential exposures ever recorded.
Team PCP compromised LiteLLM in what CloudSEK describes as the largest supply chain attack targeting AI infrastructure to date.
Pipelines trust dependencies by mutable references that an attacker can silently repoint, which is why the attack worked the same way on every platform.
Nearly a thousand victim organizations leaked session tokens, and hundreds leaked cloud keys and source control credentials; StepSecurity says a single one of these is often enough to move from a build runner into production or into the next open source project.
Team PCP, also written TeamPCP, is the threat actor behind a chain of high-profile open source compromises in 2026; its signature is a repeatable playbook rather than a single piece of malware: compromise a widely trusted component, plant a credential stealer, collect the secrets CI/CD runners load into memory, and reinvest those credentials into the next compromise.
CloudSEK's Threat Intelligence team cataloged the exposure and published a searchable dataset so organizations can check whether they appear in it.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet1 distinct publisher
security
A poisoned Nx Console build rode VS Code's auto-update into GitHub's own repositories1 distinct publisher
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
science
LiteLLM's 40 minutes on PyPI: 153GB of loot, 2,488 named orgs, and the victims nobody can name1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Precise numbers, a single interested witness
Every figure in this story — 78,330 secrets, 2,186 organizations, 76 of Trivy's 77 tags, more than 230 Azure DevOps shops, nearly a thousand leaked session tokens — reaches us through StepSecurity's reading of a list CloudSEK published. The list is described as searchable, so it is checkable in principle; nothing in our coverage shows anyone outside those two firms having checked it. The named compromises are specific enough to be proved wrong later, which is more than can be said for the rankings attached to them.
Thousands of pipelines, counted in one place
What spreads here is not a product but a campaign, and its footprint is broad and named: a GitHub Action, a Checkmarx action, a PyPI package, an AI gateway, plus victims sitting on GitLab, Azure DevOps and, in one subset, no pipeline at all. That breadth is why the score is high. What keeps it from going higher is that the entire distribution is one firm's decode of one dataset — if the decode is wrong, every platform ranking in the story moves with it.
Real breach, vendor-sized frame
The events read as real; the packaging is doing extra work on top of them. 'One of the largest credential exposures ever recorded', 'the largest supply chain attack targeting AI infrastructure to date' and the claim that one person with an AI coding agent now matches nation-state capability are all characterizations whose supporting evidence is described rather than shown. Strip the superlatives and a serious cross-platform pipeline compromise survives intact — which is the tell that they were decoration.
The finding and the fix ship in one post
StepSecurity sells CI/CD runtime security, and the piece runs a clean arc from other people's leaking build systems to precisely the controls it sells: egress restrictions on runners, runtime monitoring, governance over which actions may execute with secrets in scope. It also credits its own research team with discovering or first reporting much of the 2026 wave and links onward to its own threat intel and mid-year update. None of that makes the counts wrong; it does mean the framing that makes them frightening is the framing that sells.
Enough to characterize, not to certify
We can say confidently who is talking, what they sell, and which details are concrete enough to be checked later — Trivy's tag count and the platform mix chief among them. What this reporting alone cannot give us is validation of the counts, any sign a stolen credential was used against a victim, or what happened after disclosure. No rotation timeline, no victim confirmation, no second reader of CloudSEK's list.