SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More” inside PodZeus.
This episode of SANS Stormcast covers a major supply chain compromise tied to Team PCP, a malicious actor targeting open-source projects and development environments. The breach began when Team PCP exploited a privileged personal access token from Aqua Security to inject malicious code into the Trivi Visual Studio Code extension—a free vulnerability scanner used widely in development workflows. The attackers replaced existing versions rather than releasing new ones, allowing the malware to persist undetected in systems that pinned version tags. The malicious payload was an info stealer that exfiltrated API keys, cloud credentials, and other secrets. The attack escalated when Light LLM, a proxy service for LLMs, was compromised through the same supply chain vector, giving attackers access to credentials for multiple large language models. Additionally, Team PCP was linked to compromising Checkmarx’s open-source tools like KICS, possibly using credentials stolen via Trivi. A new development reveals a Kubernetes wiper malware, also attributed to Team PCP, targeting systems in Iran via time zone and locale detection, and capable of spreading via SSH. The episode emphasizes the critical need for robust secrets management and pinning dependencies by Git hash rather than version tags to prevent such attacks. The host, Johannes Ulrich, underscores that this incident highlights systemic weaknesses in software supply chains and the dangers of poor credential hygiene. He warns that Trivi’s popularity means many organizations may be unknowingly compromised, and urges vigilance across all dependencies. He also notes that Team PCP’s shift from credential stealing to destructive wiper malware signals a more aggressive and potentially state-sponsored campaign. The episode concludes with a call to action: organizations must adopt stronger secret management practices and treat supply chain security as a top priority. The host also promotes his upcoming courses in Orlando and San Diego.
Pin dependencies by Git hash instead of version tags to prevent replacement attacks.
Weak secrets management is a root cause of widespread supply chain breaches.
Team PCP is using both credential stealers and destructive wiper malware, indicating evolving tactics.
Compromised tools like Trivi and Checkmarx can lead to cascading attacks across the software ecosystem.
Monitor for indicators of compromise from trusted open-source projects, especially those with high adoption.
…and 3 more takeaways available in PodZeus
Introduction and IP KVM Detection
Johannes introduces the episode and briefly discusses the risks of IP KVM devices, particularly their use as stealthy remote access tools without software installation. He highlights detection methods via USB device strings and HDMI EDID data.
Team PCP Supply Chain Attack on Trivi
“The attacker replaced existing version... meaning that organizations using Trivi that were just pinning the version, the tag and not a GitHub commit... were now using the malicious version.”
Escalation: Light LLM and Multi-Level Compromise
“Light LLM has access to the credentials to access all these different LMs, which, well, again, is kind of what this entire sort of compromise was after.”
Team PCP’s New Wiper Malware and Broader Implications
“It will not just basically wipe out your Kubernetes infrastructure. It will also attempt to spread via SSH.”
“It will not just basically wipe out your Kubernetes infrastructure. It will also attempt to spread via SSH.”
“The attacker replaced existing version... meaning that organizations using Trivi that were just pinning the version, the tag and not a GitHub commit... were now using the malicious version.”
“Light LLM has access to the credentials to access all these different LMs, which, well, again, is kind of what this entire sort of compromise was after.”
Host
Johannes Ulrich
person
Team PCP
organization
Trivi
product
Aqua Security
organization
Light LLM
product
Visual Studio Code
product
Kubernetes
product
Checkmarx
organization
Iran
place
GitHub
other
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
