Science1 distinct publisher2 min readPublished
Unit 42 says the group backdoored Trivy, KICS, LiteLLM and Telnyx's Python SDK, tools that run inside CI with the privileges needed to reach production secrets, which is also why the headline counts deserve a slow read.
The Scientist · Science desk
Compiled by The ScientistSomething wrong?How this is made
Unit 42 states the mechanism plainly: this operation weaponizes security and developer infrastructure that inherently requires elevated privileges, which hands the attacker unimpeded access to production secrets and, from there, the option of extortion [14]. That is the part worth carrying away. A scanner that has been granted the ability to inspect what you ship is, by design, a process holding credentials that a normal application would never see.
Now the denominators. LiteLLM's documentation claims over 95 million monthly downloads [6], and Trivy and KICS are described as embedded in millions of enterprise CI/CD pipelines [7]. Those are popularity measures. They set a ceiling on who could have been touched rather than estimating who was, since a monthly download figure counts fetches, including every pipeline rerun that pulls a package fresh, and none of it is scoped to the malicious releases.
The number everyone will quote is attributed to vx-underground: over 300 GB exfiltrated from 500,000 infected machines [8]. In the same write-up's own scope summary, it is over 300 GB and 500,000 credentials [9]. A single host can yield many credentials, so the second reading is compatible with a far smaller infected population than the first. Neither version arrives with a collection method, which is the thing that would let a reader choose between them.
The firmer floor sits lower. Four named projects [2] plus 48 packages infected using harvested tokens [10] gives at least 52 affected packages [1]. Sixteen victim organizations have been published on leak sites [11], which is 0.003% of the claimed 500,000 [2]; leak-site publication is a negotiating step, not a census.
There is also a seam in the timeline. The escalating sequence is dated late February through March 2026 [1], while the group's move to smash-and-grab supply chain compromise is dated to mid-March 2026 [15], leaving the earlier weeks of the same campaign window doing something the account does not classify the same way [3]. The group's earlier notoriety came from exploiting React2Shell, CVE-2025-55182, for remote code execution in cloud endpoints [16], a different operational mode from the one on display here.
The practical need is a list of releases to grep for, not another aggregate figure. Unit 42 points to interim guidance for identifying vulnerable packages and hardening CI/CD policy [18], and that is where version specificity has to live; four project names will not resolve a build log. Until then the tractable audit is not the package list but the runner: which credentials were live inside those workflows during the window, and what each of them still opens.
Ranked by verification strength, evidence, and original report placement.
The malware silently extracts cloud access tokens, SSH keys and Kubernetes secrets.
The attacks also establish persistent backdoors for lateral movement across clusters.
Between late February and March 2026, threat group TeamPCP conducted a calculated, escalating sequence of supply chain threats.
TeamPCP compromised the vulnerability scanners Trivy (Aqua Security) and KICS (Checkmarx), the AI gateway LiteLLM (BerriAI), and the official Python SDK of Telnyx.
The attacks injected malicious infostealer payloads directly into GitHub Actions and PyPI registries, where they executed during routine automated workflows.
LiteLLM is an open-source library used to route requests across LLM providers, and its documentation states it has over 95 million monthly downloads.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
science
A backdoored litellm release turns every CI job that installed it into a credential incident1 distinct publisher
security
A misconfigured GitHub Actions workflow handed TeamPCP the token that poisoned five ecosystems1 distinct publisher
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
security
Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 20201 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Forensically granular, entirely unilateral
The mechanical detail is the strong part and it is strong: a named service account, an imposter commit, 76 of 77 tags force-pushed, three versions of kamikaze.sh, /proc memory reads to defeat secret masking. That is the texture of first-hand telemetry, not repackaged rumour. The weak part is that every line of it comes from Unit 42, and the two numbers a reader will actually remember are the two Unit 42 sourced elsewhere and hedged — 300 GB and 500,000, relayed as what vx-underground believes and softened to 'may have' in the vendor's own summary.
Enormous install base, sixteen confirmed casualties
The exposure surface is real and quantified at one end: LiteLLM's documentation claims 95 million monthly downloads, Trivy and KICS run inside CI everywhere, and the tainted artifacts were pushed to registries developers pull automatically. The confirmed end is much thinner — 16 organizations, all self-published by the attackers, and 48 downstream packages that are counted but never named. Real spread almost certainly sits between those poles; this reporting does not let you locate it.
The counts outrun the receipts
Our headline framing asks for a slow read of the counts, and the arithmetic bears that out. Sixteen named organizations against a claimed 500,000 infections is three thousandths of one percent, a ratio Unit 42 presents without reconciling. The same 500,000 is machines in one paragraph and credentials in another. The stated window opens in late February while the pivot to supply chain work is dated mid-March, so the earliest weeks are a credential-rotation lapse being counted inside a campaign Unit 42 says had not started yet. None of this makes the compromise small — the privileged-tooling argument is the genuinely serious part and is arguably understated next to the tonnage.
Threat research with a price list
Palo Alto Networks publishes the research, and the research ends by naming five Palo Alto products that protect customers from it, then offers a Cloud Security Assessment and an incident response engagement. The certificate telemetry that anchors the infrastructure findings is itself a Cortex Xpanse output. That is not a reason to discount the technical work, which is specific enough to be falsifiable — but an account whose subject is 'the scanners you trust betrayed you' and whose remedy is 'buy our detection layer' has an obvious directional pull on how big the numbers get to sound.
Believable mechanics, unverified magnitude
We would bet on the technical narrative — the Trivy repository compromise, what kamikaze.sh does on a runner, CanisterWorm's existence — and would not yet bet on the scale. One publisher, commercially interested, five months after the events, with no vendor statements from any of the four compromised projects and no version-level indicators a reader could use to self-check. A second independent account would move this materially in either direction.