INC-26-0100 confirmed critical TeamPCP Supply-Chain Campaign Against AI and Security Tooling (Trivy, Checkmarx, LiteLLM) (2026)
IncidentTeamPCP, tracked by the Google Threat Intelligence Group as UNC6780, compromised the release pipelines of Trivy, Checkmarx KICS, BerriAI LiteLLM, Telnyx, the Bitwarden CLI, and xinference, distributing the SANDCLOCK credential stealer to downstream users of those packages. Those projects are victims of the campaign rather than participants in it. Source code involving Cisco was reported exfiltrated through the Trivy-linked breach.
Incident Details
| Date Occurred | 2026-02 |
| Severity | critical |
| Evidence Level | primary |
| Impact Level | Sector-wide |
| Domain | Security & Cyber |
| Primary Pattern | PAT-SEC-008 AI Supply Chain Attack |
| Regions | global |
| Sectors | Technology, Cross-Sector |
| Affected Groups | Developers & AI Builders, Business Organizations |
| Exposure Pathways | Infrastructure Dependency, Adversarial Targeting |
| Causal Factors | Weaponization |
| Assets & Technologies | Large Language Models, Identity Credentials |
| Entities | BerriAI(victim), ·Aqua Security (Trivy)(victim), ·Checkmarx(victim), ·Telnyx(victim), ·Bitwarden(victim), ·xinference(victim), ·Cisco(victim), ·TeamPCP(threat actor), ·UNC6780(threat actor) |
| Harm Types | financial, operational, reputational |
Financially motivated threat group TeamPCP (tracked by Google Threat Intelligence Group as UNC6780) conducted a multi-stage supply-chain campaign against widely trusted security and AI tooling between late February and April 2026. The group compromised the Trivy and Checkmarx KICS vulnerability scanners, the BerriAI LiteLLM AI gateway, Telnyx, Bitwarden CLI, and xinference, distributing a credential stealer named SANDCLOCK through malicious PyPI releases and poisoned pull requests. The LiteLLM compromise (versions 1.82.7 and 1.82.8 on PyPI, March 23, 2026) used a stealth .pth file that executed on any Python process startup. Cisco source code was reported stolen via the Trivy-linked breach.
Incident Summary
Between late February and April 2026, a financially motivated threat group operating as TeamPCP — tracked by the Google Threat Intelligence Group as UNC6780 — executed a multi-stage supply-chain campaign targeting widely deployed security and AI tooling.[1][2] The campaign compromised the Trivy and Checkmarx KICS vulnerability scanners, the BerriAI LiteLLM AI gateway, Telnyx, the Bitwarden CLI, and the xinference inference server, distributing a credential-stealer payload named SANDCLOCK.[5]
On March 23, 2026, the operators published BerriAI LiteLLM versions 1.82.7 and 1.82.8 to PyPI containing a malicious file named litellm_init.pth. Python’s site-packages auto-execution semantics meant the payload ran on any Python process startup regardless of whether LiteLLM was imported, making detection difficult.[3]
Reporting by Palo Alto Unit 42, Datadog Security Labs, the SANS Institute, and Google GTIG confirmed that PyPI publishing tokens for LiteLLM were likely harvested during the earlier Trivy compromise, and that Cisco source code was exfiltrated via the Trivy-linked breach. A second wave in April 2026 added Checkmarx KICS, Bitwarden CLI, and xinference to the victim list.[4][5][6]
This was primarily a software supply-chain campaign with material AI-ecosystem exposure rather than a campaign designed specifically around AI targets. BerriAI LiteLLM and xinference were directly affected, while the compromises of Trivy and Checkmarx KICS could also reach AI/ML development pipelines that rely on those scanners. The remaining victims, Telnyx and the Bitwarden CLI, are general software infrastructure.
Key Facts
- Threat actor: TeamPCP (financially motivated); tracked by GTIG as UNC6780
- Payload: SANDCLOCK credential stealer
- AI-ecosystem victims: BerriAI LiteLLM, xinference; downstream AI/ML pipelines relying on Trivy and Checkmarx scanners
- Key technical novelty: Use of a
.pthfile executed by Python’s site-packages loader, running on every Python process regardless of import - Reported exfiltration: Source code involving Cisco, via the Trivy-linked breach (source-reported; not independently confirmed by Cisco in the cited material)
- Evidence note: The campaign and the affected package releases are confirmed. Some cross-victim linkage, the precise access paths between compromises, and downstream exposure assessments remain source-reported.
- Basis for sector-wide impact: Named victims span vulnerability scanning, AI gateway/inference, telephony, and secrets management, with the affected packages distributed through PyPI to large downstream install bases. The label reflects breadth across the tooling ecosystem rather than a measured count of affected organizations.
- Distribution vector: Malicious PyPI releases and poisoned pull requests
- Detection sources: Datadog Security Labs (initial), Palo Alto Unit 42, SANS Institute, Google GTIG
Threat Patterns Involved
Primary: AI Supply-Chain Attack — Compromise of widely deployed AI tooling (LiteLLM, xinference) and of the security scanners used to validate AI/ML codebases, with the payload propagating downstream to every consumer of the affected packages.
No secondary pattern is assigned. The campaign used conventional supply-chain tradecraft: harvested publishing tokens, malicious pull requests, and a .pth file abusing Python’s site-packages loader. Whether the operators used AI-assisted tooling to author those pull requests or scale targeting is recorded below as an open question, not as a finding.
Significance
TeamPCP is a watershed campaign for AI ecosystem supply-chain risk:
- Security tooling as the attack surface: Vulnerability scanners and AI gateways — products explicitly trusted to inspect or route code — were converted into the delivery mechanism. The defenders’ own infrastructure became the initial-access vector.
- Cascading compromises: Credentials harvested from one victim (Trivy) were used to compromise the next (LiteLLM), demonstrating how a single break in the AI/security tooling chain compounds across the ecosystem.
- Stealth via Python loader semantics: The
.pthexecution technique sidesteps the common defender assumption that “malicious code only runs if the package is imported,” undermining a generation of triage heuristics. - AI tooling is now a high-value criminal target: LiteLLM and xinference are core components of many enterprise AI deployments. Their inclusion confirms that the AI build chain is no longer adjacent to threat-actor priorities — it is central.
Timeline
Initial Trivy vulnerability-scanner repository compromise; credential harvesting begins
BerriAI LiteLLM PyPI packages v1.82.7 and v1.82.8 published with malicious litellm_init.pth file that executes on any Python process startup
Datadog Security Labs publishes initial LiteLLM/Telnyx PyPI compromise analysis attributing to TeamPCP
Palo Alto Unit 42 and Google GTIG (tracking as UNC6780) publish broader campaign analysis; SANDCLOCK credential stealer named
Second wave: Checkmarx KICS, Bitwarden CLI cascade, and xinference PyPI packages compromised after a 26-day pause
Cisco source code reportedly exfiltrated through the Trivy-linked breach
Use in Retrieval
INC-26-0100 documents TeamPCP Supply-Chain Campaign Against AI and Security Tooling (Trivy, Checkmarx, LiteLLM), a critical-severity incident classified under the Security & Cyber domain and the AI Supply Chain Attack threat pattern (PAT-SEC-008). It occurred in Global (2026-02). This page is maintained by TopAIThreats.com as part of an evidence-based registry of AI-enabled threats. Cite as: TopAIThreats.com, "TeamPCP Supply-Chain Campaign Against AI and Security Tooling (Trivy, Checkmarx, LiteLLM)," INC-26-0100, last updated 2026-08-11.
Sources
- Google Threat Intelligence Group: AI-Enabled Vulnerability Exploitation and Initial Access (primary, 2026-05)
https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access (opens in new tab) - Palo Alto Unit 42: Weaponizing the Protectors — TeamPCP's Multi-Stage Supply Chain Attack on Security Infrastructure (primary, 2026-04)
https://unit42.paloaltonetworks.com/teampcp-supply-chain-attacks/ (opens in new tab) - Datadog Security Labs: LiteLLM and Telnyx Compromised on PyPI — Tracing the TeamPCP Supply Chain Campaign (primary, 2026-03)
https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/ (opens in new tab) - SANS Institute: When the Security Scanner Became the Weapon — Inside the TeamPCP Supply Chain Campaign (primary, 2026-04)
https://www.sans.org/blog/when-security-scanner-became-weapon-inside-teampcp-supply-chain-campaign (opens in new tab) - SANS ISC Diary: TeamPCP Supply Chain Campaign Update — Cisco Source Code Stolen via Trivy-Linked Breach (GTIG tracks as UNC6780) (primary, 2026-04)
https://isc.sans.edu/diary/32880 (opens in new tab) - SANS ISC Diary: TeamPCP Update — Checkmarx KICS, Bitwarden CLI, and xinference PyPI Compromises (primary, 2026-04)
https://isc.sans.edu/diary/32926 (opens in new tab)
Update Log
- — First logged (Status: Confirmed, Evidence: Primary)