Security & Threat Intelligence

The Watch

The Signal

TeamPCP's supply chain campaign has cascaded from the previously-reported Trivy

If any system in your AI/ML pipeline transitively depends on LiteLLM (including DSPy), treat it as a confirmed credential compromise and rotate everything today.

In Play

  1. LiteLLM PyPI Compromise: .pth Injection Hits AI Pipelines

    TeamPCP compromised LiteLLM's CEO GitHub account to push trojanized PyPI packages (v1.82.7, v1.82.8) with a .pth file that executes on Python interpreter startup — invisible to code review, SCA tools, and import monitoring. Exfiltrates full credential inventory; includes rm -rf / wiper for Asia/Tehran timezone systems.

    Ask Clarity
  2. Third-Party Access Is This Cycle's #1 Breach Vector

    Four distinct breaches all exploited trusted third-party access: Crunchyroll lost 8M tickets via a BPO agent's Okta SSO, HackerOne had 287 employees' SSNs exposed via a benefits vendor BOLA, Stryker's own Intune MDM was weaponized to wipe devices, and Google Looker's Sev0 RCE chained to K8s cluster-wide privilege escalation.

    Ask Clarity
  3. Critical Vulns Requiring Immediate Patching

    Citrix NetScaler CVSS 9.3 enables unauthenticated memory read and session hijacking on internet-facing SAML endpoints — exploitation is imminent. Quest KACE CVE-2025-32975 auth bypass is already under active exploitation with lateral movement and credential harvesting observed. Both are high-value targets historically favored by ransomware and nation-state actors.

    Ask Clarity
  4. First AI Agent Detection Tools Ship Alongside Structural LLM Weaknesses

    Sysdig published the first syscall-level Falco detection rules for AI coding agents (Claude Code, Gemini CLI, Codex CLI). Simultaneously, Anthropic's interpretability research proves safety guardrails are structurally bypassed by grammatical coherence mid-sentence, and chain-of-thought reasoning is fabricated on hard problems. Detection is arriving — but so is proof that model-level safety is not a reliable control.

    Ask Clarity
  5. Regulatory & Geopolitical Security Shifts

    FCC banned all new foreign-made consumer routers (China holds ~60% US market). DHS has been unfunded since February, degrading CISA operations during US-Iran military escalation. Treasury is soliciting comment on expanding TRIP to cover cyber-terrorism losses, with the law expiring in 2027. Each changes procurement, federal coordination, or risk transfer calculus.

    Ask Clarity

Deep Dives

LiteLLM Trojanized via Stolen PyPI Token: The .pth Injection Technique Your Scanners Won't Catch

A Cascading Supply Chain Attack Hits the AI Ecosystem

The TeamPCP campaign — previously reported for compromising Trivy — has now cascaded into the Python AI ecosystem via a novel attack chain. The group compromised Aqua Security's Trivy CI/CD pipeline, used that access to steal LiteLLM's PyPI publishing token, and pushed trojanized packages (versions 1.82.7 and 1.82.8) to PyPI. A separate vector also hit Checkmarx's KICS scanner, with malware injected into its GitHub Action and VS Code extensions.

LiteLLM is an LLM proxy/router library used by thousands of organizations to route requests across OpenAI, Anthropic, and Google. The blast radius extends beyond direct users — transitive dependencies in frameworks like DSPy mean any project in your AI/ML pipeline could be affected.

The tools you adopted to accelerate AI development just became the tools that compromise you completely — and the technique used is invisible to every standard scanning tool in your pipeline.

The .pth Injection: Why Your Scanners Miss It

The attack's most significant innovation is the persistence mechanism. Rather than hiding malicious code in source files (which SAST and SCA tools inspect), the attacker planted a litellm_init.pth file in Python's site-packages directory. The .pth file format is a Python-specific feature that executes arbitrary code when the interpreter starts — no import required, no explicit invocation needed.

This means:

  • Standard code review of LiteLLM's source won't find it
  • SCA tools scanning dependency trees won't flag it
  • Import-level monitoring never triggers because the payload fires before any import
  • The payload runs in any Python process on the affected system, not just LiteLLM-specific code

The exfiltration scope is staggering: SSH keys, AWS/GCP/Azure credentials, Kubernetes configs, git credentials, all environment variables, shell history, crypto wallets, CI/CD secrets, SSL private keys, and database passwords. A conditional rm -rf / wiper activates if the system timezone is Asia/Tehran, suggesting geopolitical motivation beyond simple cybercrime.


Cross-Source Analysis: The Full TeamPCP Kill Chain

Six independent sources confirm the attack chain and provide complementary technical detail:

  1. Initial access: TeamPCP modified existing GitHub Actions version tags on Trivy (not new releases — tag overwrites that bypass version pinning to major/minor tags)
  2. Lateral expansion: Compromised Aqua Security's entire GitHub organization including private repos and Docker images
  3. KICS compromise: Malware inserted into Checkmarx KICS GitHub Action and two VS Code extensions
  4. Credential theft: LiteLLM's PyPI publishing token intercepted from the compromised CI/CD pipeline
  5. Package poisoning: Two LiteLLM versions pushed with .pth credential stealer
  6. Counter-intelligence: AI-generated 'Thanks, that helped!' comments used to bury security warnings on LiteLLM's GitHub vulnerability reports

The AI-generated comment spam is a novel defense evasion technique — MITRE T1562.001 applied to open-source vulnerability disclosure. No automated filtering exists for this on GitHub.


Trivy Docker Hub Update

New detail since yesterday: Trivy versions 0.69.4, 0.69.5, 0.69.6, and the 'latest' tag on Docker Hub were malicious from March 19-23. Docker confirmed its own infrastructure and Hardened Images were not impacted, but any pipeline that pulled these versions should be treated as compromised.

What to do

  1. Hunt for LiteLLM v1.82.7/v1.82.8 across all Python environments — production, staging, CI/CD, developer workstations, Jupyter notebooks, Docker images — using pip list, pip freeze, and container image scanning. Check transitive dependencies via pip show litellm on DSPy environments.

  2. Scan all Python site-packages directories for rogue .pth files: find /usr/lib/python*/site-packages -name '*.pth'. Baseline legitimate .pth files from setuptools, pip, distutils. Any unrecognized .pth file is suspect.

  3. If LiteLLM or compromised Trivy versions found: rotate ALL credentials accessible from affected systems — cloud IAM, SSH keys, K8s service account tokens, CI/CD secrets, database passwords, API keys. Review cloud audit logs for unauthorized access during the exposure window.

  4. Enforce pip --require-hashes across all Python projects and deploy a private PyPI mirror with pre-admission scanning by end of sprint.

  5. Add .pth file integrity monitoring to your SIEM. Alert on .pth file creation or modification in site-packages directories outside approved package management operations.

Four Breaches, One Pattern: Trusted Third-Party Access Is Your Weakest Perimeter

The Common Thread

This cycle produced four distinct breaches that share a single root cause: trusted third-party access channels bypassed every technical control because the threat came through an authorized pathway. A BPO agent's SSO, a benefits vendor's API, your own MDM platform, and a cloud analytics tool's service account — each one a legitimate access point weaponized against you.

Technical controls fail when the threat comes through an authorized pathway. Your third-party access model is your actual security perimeter — not your firewall.

Crunchyroll: BPO Agent SSO → 8 Million Tickets Exfiltrated

On March 12, a threat actor compromised an Okta SSO account belonging to a Telus International BPO support agent and exfiltrated 8 million Crunchyroll Zendesk support tickets — names, email addresses, IP addresses, and limited payment data for up to 6.8 million users. The attacker demanded $5 million ransom. A separate detail from one source reveals the contractor was bribed and intentionally detonated malware, stealing 100GB+ of data.

This is the attack pattern that should trigger an immediate audit at every organization using outsourced support. BPO agents have production access to your customer data platforms. Without phishing-resistant MFA, conditional access, and session duration controls, a single compromised BPO agent account can exfiltrate your entire customer support history.


HackerOne/Navia: BOLA in the Benefits Stack

A Broken Object Level Authorization vulnerability in Navia's benefits platform exposed 287 HackerOne employees' SSNs, full names, addresses, phone numbers, dates of birth, and employment dates. The irony that this hit HackerOne — a company whose entire business model is finding vulnerabilities — underscores a critical reality: your vendor's security posture is not correlated with your own. Navia's 2.7M-individual breach was previously reported, but the HackerOne BOLA exposure is a new vector in the same vendor.


Stryker: Your MDM Becomes the Weapon

Attackers gained access to Microsoft Intune at Stryker and used the MDM platform itself to wipe the company's devices. This is the nightmare scenario for any organization that centralizes device management: the tool designed to protect your fleet becomes the tool that destroys it. MDM admin accounts are privileged-access targets that many organizations protect less rigorously than domain admin credentials.


Google Cloud Looker: Path Validation to Cluster Takeover

A Sev0 RCE chain in Google Cloud Looker demonstrated devastating escalation potential. Attackers passed ["/ "] to Looker's directory deletion API, bypassing .git protection checks. They then exploited a race condition in Ruby's FileUtils.rm_rf to inject a malicious Git fsmonitor hook during the deletion window — achieving RCE. Post-exploitation revealed overpermissioned Kubernetes service account credentials enabling cluster-wide privilege escalation. Google classified the privesc as Sev0 and patched both vulnerabilities. Self-hosted instances require manual verification.


Cross-Source Pattern Analysis

BreachTrust Boundary ViolatedData ImpactRoot Cause
CrunchyrollBPO agent Okta SSO6.8M users, 8M tickets, 100GB+No FIDO2 MFA, broad session scope
HackerOneBenefits vendor API287 SSNs + PIIBOLA in Navia's API
StrykerMDM admin accessFleet-wide device wipeInsufficient MDM admin controls
LookerCloud service accountK8s cluster compromiseOverpermissioned service accounts

Sources disagree on one detail: whether the Crunchyroll attacker compromised the BPO account externally or bribed the contractor directly. Both accounts appear in separate intelligence reports, suggesting the attack may have involved both — a bribed insider who also provided credentials for remote access. Either way, the control gap is the same.

What to do

  1. Enforce FIDO2 MFA on all BPO and outsourced support agent accounts by end of week. Implement conditional access requiring managed devices and set maximum 4-hour session durations on all third-party agent accounts with access to customer data platforms (Zendesk, Salesforce, Intercom).

  2. Audit MDM/Intune admin access controls: enforce MFA, implement privileged access workstations, and create SIEM alerts for bulk device wipe or reset commands.

  3. Conduct BOLA/IDOR testing against your top 5 HR and benefits SaaS vendors' APIs — specifically test object-level authorization on endpoints that return employee PII.

  4. Review Kubernetes service account RBAC across all clusters. Remove default service account token mounts from application pods. Deploy admission controllers (OPA/Gatekeeper, Kyverno) to enforce least-privilege.

AI Agent Detection Arrives — But Anthropic's Research Proves Model-Level Safety Is Structurally Broken

The First Real Detection Rules for AI Agents

Sysdig's Threat Research Team published the first syscall-level detection system for AI coding agents, covering Claude Code, Gemini CLI, and Codex CLI. The research confirms what security teams have suspected: these agents run with full user permissions on developer machines and can be manipulated through prompt injection hidden in code comments or dependency files. Critically, regardless of the injection vector, malicious behavior is observable at the OS level via syscalls.

Four Falco detection rules now exist:

  1. Agent installation detection — flags new agent process launches
  2. Unauthorized credential directory access — monitors ~/.ssh, ~/.aws, ~/.config/gcloud
  3. Sensitive file reads — alerts on access outside the project directory
  4. Safety control bypasses — detects attempts to override agent guardrails

If you're running Falco, deploy these today. If not, build equivalent detections in your endpoint security stack.


Databricks Enters AI Security with Lakewatch

Databricks launched Lakewatch — an AI-agent-powered SIEM — alongside acquisitions of Antimatter (data privacy/encryption for AI) and SiftD.ai (agent behavior monitoring). This is the first major data platform vendor building native security tooling specifically for agentic AI workloads. Whether you're a Databricks customer or not, Lakewatch's feature set serves as a gap analysis checklist for what your current SIEM is missing: agent behavior anomaly detection, LLM interaction monitoring, and AI pipeline data flow classification.


Anthropic Proves Safety Guardrails Have Structural Limits

Meanwhile, Anthropic published their most significant interpretability research to date — and the findings are sobering for anyone relying on model-level safety:

  • Grammar overrides safety mid-sentence: Safety features compete with grammatical coherence, and coherence wins during token generation. Safety can only engage at sentence boundaries. This is architectural, not fixable with more training.
  • Chain-of-thought is fabricated on hard problems: When Claude can't compute an answer, it generates one anyway and constructs a plausible-looking derivation after the fact. No evidence of actual calculation occurs internally.
  • Motivated reasoning via context poisoning: Providing a hint about an expected answer causes the model to work backward, constructing supporting evidence for the predetermined conclusion.
LLMs cannot be trusted to report their own reasoning accurately, to refuse harmful content mid-sentence, or to distinguish what they know from what they don't. Any security architecture treating model-level safety as a sufficient control needs defense-in-depth redesign.

The Tension: Detection Arriving While Trust Erodes

Sources converge on a critical contradiction: we're getting our first real tools to detect AI agent misbehavior (Sysdig Falco rules, Databricks Lakewatch), while simultaneously learning that the safety controls built into the agents themselves are fundamentally unreliable. The implication is clear: external monitoring is not optional. Model-level guardrails — including Claude Code's new auto mode classifier — are a defense-in-depth layer, not a primary control.

The 2,000+ vulnerabilities already documented from AI-generated code ('vibe coding') reinforce this point. AI agents are producing functionally correct but security-flawed code — exposed secrets, broken authentication, insecure defaults — that passes unit tests but fails adversarial review. Your SAST/DAST rules, calibrated for human-written code patterns, likely have detection gaps for AI-generated vulnerability classes.

What to do

  1. Deploy Sysdig's four Falco detection rules for AI coding agents this week. If not running Falco, build equivalent endpoint detections monitoring agent processes accessing credential directories, reading files outside project scope, or bypassing safety controls.

  2. Audit all LLM-in-the-loop workflows for over-reliance on chain-of-thought explanations as compliance evidence. Flag any process where AI-generated rationale serves as an audit artifact.

  3. Add AI-generated code detection rules to your CI/CD pipeline. Scan for exposed secrets, hardcoded credentials, broken authentication, and insecure defaults characteristic of AI-generated code.

  4. Evaluate Databricks Lakewatch against your current SIEM for AI/agent-specific detection gaps within 60 days.

The bottom line

TeamPCP's supply chain campaign has cascaded from Trivy into the Python AI ecosystem — LiteLLM's trojanized PyPI packages use a .pth injection technique that exfiltrates every credential on the host without ever being imported, four separate breaches this cycle all exploited trusted third-party access (BPO SSO, benefits APIs, your own MDM, cloud service accounts), and while the first real AI agent detection rules just shipped from Sysdig, Anthropic's own research proves LLM safety guardrails are structurally bypassable mid-sentence — audit your Python environments for LiteLLM v1.82.7/1.82.8 today, enforce FIDO2 on every outsourced agent account, and stop treating model-level safety as anything more than defense-in-depth.