Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A threat actor tracked as TeamPCP has conducted a coordinated supply chain attack against multiple developer and security tools used widely in enterprise DevSecOps pipelines, including Checkmarx KICS, Trivy, VS Code extensions, and the LiteLLM AI library. The attack targets upstream components such as GitHub Actions and open-source package repositories, injecting malicious code into tooling that runs with elevated trust during builds, scans, and code development. Organizations using any of these tools in automated pipelines face risk of backdoor installation, credential theft, and downstream compromise of production environments, with activity assessed as ongoing by multiple vendors.

Author

Tech Jacks Solutions