Security1 distinct publisher3 min readPublished
Two alleged TeamPCP operators are in custody, and Flare's account of the March 2026 chain puts the root cause inside Aqua Security's Trivy build workflow, where a leaked service-account token survived an incomplete rotation.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The cascade ran on tokens. TeamPCP pulled a service-account token out of a misconfigured GitHub Actions workflow in Aqua Security's Trivy, the most widely deployed open-source vulnerability scanner [7]. On March 19 it published a malicious Trivy release across every distribution channel at once, so consuming builds fetched the expected artifact from the expected place and took a credential stealer with it [9]. LiteLLM's build pipeline was one of those consumers. It ran the poisoned scanner, and the attackers came away with LiteLLM's PyPI publishing token [10]. Two backdoored LiteLLM releases went out on March 24 [11].
March 19 to March 24 is five days [19]. The longer interval is upstream: Aqua rotated credentials after the February theft and missed some, and the leftover access held [8], which put roughly three weeks between the token theft and the release that used it [20].
Registry-side trust never had a vote here. Both malicious releases were published with the projects' own credentials through the projects' own channels [9][11]. The controls with a chance of breaking that are the permission scope on the workflow holding the token, and whether a rotation reaches every credential the workflow ever issued. LiteLLM's leg is the more portable finding: a build job that executes a third-party binary while holding a publishing token has handed the binary the token [10].
Flare's post is the source for the arrests. It says two people behind the attack were arrested on the day of publication [1], and does not name the jurisdiction, the charges, or the individuals [22]. Flare points to other independent investigations, including by Brian Krebs [17]. It also counts four controls that would have broken the chain and names credential hygiene as one of them [15].
The attribution came from the group's own volume. Flare's deanonymization started with a single alias and traced every account it touched [16]. TeamPCP ran Telegram channels, posted on X as @pcpcats before that account was deleted, taunted victims, and gave a press interview, and the reused handles, avatars, and infrastructure references that habit produced are what made an operator identifiable [13]. In an interview with Forbes, the group called itself "a loose-knit group of teenagers and young adults who couldn't find paying work, so they turned to cybercrime" [14].
Read against the crew's history, March 2026 shows the same operators wielding far more leverage without any real gain in skill. In late 2025 an automated scanner swept for exposed Docker APIs, Kubernetes control planes, Ray dashboards, and Redis instances, deploying containers that turned each host into another scanner and proxy node [4]. Flare's honeypots fingerprinted 185 Docker compromises in one phase [5]. Revenue came from three sources: XMRig mining, a rented proxy network, and stolen data leaked or sold for extortion [18]. Early 2026 was the pivot into the supply chain, aimed at the security tools other companies trust [21]. The useful number in your own environment is how many build jobs can read a publishing token while running code somebody else shipped.
Ranked by verification strength, evidence, and original report placement.
For five days in March 2026 a single stolen token let one group poison five software ecosystems, including a package downloaded 95 million times a month.
Aqua rotated credentials but missed some, and the leftover access held.
Flare's deanonymization process started with a single TeamPCP alias and traced every account it touched from there, across accounts, credentials, and infrastructure.
Flare's honeypots recorded the activity firsthand and fingerprinted 185 Docker compromises in one phase.
TeamPCP broke out in December 2025 with a React2Shell campaign against Next.js applications; the group's own control-server dashboard claimed more than 59,000 servers compromised in under 48 hours.
In late February 2026 TeamPCP exploited a misconfigured GitHub Actions workflow in Aqua Security's Trivy, described as the most widely deployed open-source vulnerability scanner, and stole a service-account token.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
build
56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet1 distinct publisher
build
Flux moves GitOps' source of truth into registries you own, and mirroring becomes the prerequisite1 distinct publisher
product
Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One interested vendor, no primary corroboration
Every specific in the cluster comes from a single threat-intelligence vendor blog whose body text is truncated mid-sentence. The chain is internally coherent and precisely dated, and Flare has first-party honeypot telemetry, which lifts it above rumor. But there is no Aqua Security or LiteLLM statement, no affected versions or indicators, no registry data behind the 95 million downloads figure, and no law-enforcement confirmation of the arrests that anchor the story's news hook. Referenced independent work (Krebs, Forbes) is neither linked nor present.
Real dated compromises, blast radius still vendor-estimated
This is not a proposal or a lab result: poisoned artifacts were actually published to production distribution channels on specific dates, and downstream propagation from Trivy into LiteLLM's PyPI releases is a concrete second-order compromise. Flare's own honeypots observed the earlier cloud-exploitation phase. What keeps the score mid-range is that the scale of real-world exposure - five unnamed ecosystems, 'thousands' of pipelines, 95 million monthly downloads, 59,000 servers - is either vendor-estimated or attacker self-reported, with no independent victim or registry measurement.
Narrative certainty ahead of the verifiable record
The framing - arrests today, one token, five ecosystems, five days - is tighter and more conclusive than what the published material substantiates. The arrests carry no jurisdiction, charges or names; the five ecosystems are never listed; the largest reach numbers are attacker-sourced or unsourced; the actor revenue hierarchy is unquantified; and the deanonymization walkthrough stops mid-sentence before the identification is closed. The underlying technical chain is plausible and specifically dated, so the gap is moderate overstatement of certainty and scale rather than fabrication.
Vendor case study demonstrating its own platform
The post is authored by Flare's Emerging Threats Team and structured as a walkthrough of what the Flare platform and its Threat Flow AI analysis tool can do, using the firm's honeypots and a same-day arrest news hook. Attribution success stories are direct marketing for threat-intelligence tooling, which creates incentive to present a clean, conclusive chain, to foreground the vendor's role relative to other investigators it acknowledges, and to omit the caveats that would soften the demonstration.
Coherent single-source account, unconfirmed at the edges
Confidence in the technical spine is fair: the dates, the token-rotation failure and the Trivy-to-LiteLLM propagation are specific, internally consistent and partly backed by first-party telemetry. Confidence in the story as published is limited by the absence of any second publisher, the lack of statements from the affected projects and the arresting authority, the missing indicators and version strings, and a truncated body that omits three of the four defensive controls and the closing attribution steps.