Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Two separate threat actors, including a group tracked as TeamPCP, compromised three widely used open-source developer tools in March 2026: Trivy (a container and code vulnerability scanner), Axios (a JavaScript HTTP client), and LiteLLM (an AI/LLM proxy library). Attackers injected malicious code into published package releases by exploiting compromised maintainer accounts or poisoned release pipelines, targeting CI/CD environments to steal API keys, tokens, and credentials from downstream organizations. Organizations that consumed affected versions of these packages during the compromise window should treat their pipeline secrets and downstream systems as potentially exposed.

Author

Tech Jacks Solutions