FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
They Compromised the Security Scanners First. Then They Came for Your AI Tools.
NewsProgramming Languages

They Compromised the Security Scanners First. Then They Came for Your AI Tools.

via Dev.to PythonNot Elon3h ago

On March 19, 2026, a threat actor called TeamPCP compromised Aqua Security's Trivy — one of the most widely used vulnerability scanners in the world. On March 23, they compromised Checkmarx's KICS GitHub Actions. They even registered checkmarx[.]zone as a C2 domain, impersonating the legitimate security company. On March 24, they poisoned LiteLLM on PyPI. 97 million downloads per month. Versions 1.82.7 and 1.82.8 shipped with a credential-stealing backdoor that activated on every Python process startup — even without importing the library. The sequence matters. They didn't start with LiteLLM. They started with the security scanners. Why This Attack Pattern Is Terrifying Most supply chain attacks target popular packages directly. This one was different. TeamPCP's strategy: Compromise the security tools first (Trivy, Checkmarx KICS) — these run in CI/CD pipelines with elevated permissions Harvest CI/CD credentials from the compromised scanner runs Use those credentials to poison downstre

Continue reading on Dev.to Python

Opens in a new tab

Read Full Article
0 views

Related Articles

Core Web Vitals for eCommerce in 2026: Why Your Shopify Theme Might Be Killing Conversions
News

Core Web Vitals for eCommerce in 2026: Why Your Shopify Theme Might Be Killing Conversions

Medium Programming • 9m ago

Bose's flagship headphones just dropped to the lowest price I've seen on Amazon
News

Bose's flagship headphones just dropped to the lowest price I've seen on Amazon

ZDNet • 15m ago

News

RefundYourSOL (RYS): Unlocking the Full Potential of Your Solana Assets

Medium Programming • 50m ago

Lego Star Wars Smart Play Throne Room Duel and A-Wing Review
News

Lego Star Wars Smart Play Throne Room Duel and A-Wing Review

Wired • 1h ago

I found the best tech deals under $50 during Amazon's Big Spring Sale
News

I found the best tech deals under $50 during Amazon's Big Spring Sale

ZDNet • 2h ago

Discover More Articles