HomeSecurityTrivy supply chain attack: Cisco source code theft

Trivy supply chain attack: Cisco source code theft

Cisco has been the focus of a major cyberattack, as attackers exploited stolen credentials from a recent Trivy supply chain incident . The breach allowed access to the company’s internal development environments, leading to the theft of source code from both the company and its customers.

Cisco Trivy

Malicious GitHub Action as a "Trojan Horse"

According to sources familiar with the matter, the attack is linked to a malicious plugin in GitHub Actions, which was exploited to steal credentials and sensitive data. Cisco's internal security teams were able to contain the initial intrusion, but the scope of the breach appears to have affected multiple systems, including developer workstations and lab infrastructure.

The use of CI/CD tools as an entry point confirms a broader trend: attacks are shifting from end applications to the development pipelines themselves, where trust levels are higher and controls are often less stringent.

See also: Axios Supply Chain Attack: Malicious versions distribute RAT

Theft of keys and access to cloud infrastructures

During the attack, multiple Amazon Web Services were reported as exposed. These credentials were used to perform unauthorized actions on a limited number of Cisco accounts. The company immediately isolated the affected systems, reconfigured infrastructure, and performed a mass rotation of credentialsin an attempt to mitigate the risk of further exploitation.

The leakage of cloud credentials is considered particularly critical, as it can lead not only to data loss but also to the abuse of computing resources or the installation of backdoors.

Trivy supply chain attack: Cisco source code theft

Massive leak of repositories and AI projects

One of the most disturbing aspects of the case is that more than 300 GitHub repositories were allegedly cloned. These include projects related to artificial intelligence, such as AI assistants and defense solutions, as well as products that have not yet been released.

Even more serious is the fact that some of the data belongs to corporate customers, including banking organizations, BPO companies, and U.S. government agencies. This intensifies the potential legal and operational implications for Cisco.

See also: Beware! Malicious ads target Mac users

Multiple attackers and an evolving threat

Sources report that the attack involved more than one threat actor, with varying levels of activity. This suggests either a coordinated operation or exploitation of the same vulnerability by different groups.

The complexity of such attacks makes it difficult to fully assess the damage, while also increasing recovery time.

The attack on Trivy's supply chain

The root of the problem lies in the Trivy, where attackers managed to infect the project's GitHub pipeline. Through it, they distributed credential- stealing, which was integrated into official releases and automated processes.

This particular attack opened the door for to be stolen credentials from organizations using the tool, potentially impacting thousands of environments worldwide. It is a prime example of how dangerous attacks on the software supply chain can become.

Trivy supply chain attack: Cisco source code theft

TeamPCP in the spotlight

Security researchers have linked the campaign to the TeamPCP, known for using the infostealer “TeamPCP Cloud Stealer.” The group has previously targeted developer platforms such as GitHub, PyPI, NPM, and Docker, seeking access to sensitive data and development pipelines.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Russian CTRL Toolkit: New malware steals passwords and data

At the same time, attacks have been recorded on packages such as LiteLLM and projects such as Checkmarx KICS, where similar malware, affecting tens of thousands of systems.

The broader message for the industry

The Cisco incident highlights a critical reality: security is no longer limited to end-to-end applications, but extends to every stage of development. Supply chain attacks are now one of the most dangerous types of cyberthreats.

For businesses, this means an increased need for controls on third-party tools, continuous monitoring of pipelines, and adoption of zero trust practices. In an ecosystem where code is constantly shared and reused, even a small breach can have large-scale ripple effects.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS