Cisco has been the focus of a major cyberattack, as attackers exploited stolen credentials from a recent Trivy supply chain incident . The breach allowed access to the company’s internal development environments, leading to the theft of source code from both the company and its customers.

Malicious GitHub Action as a "Trojan Horse"
According to sources familiar with the matter, the attack is linked to a malicious plugin in GitHub Actions, which was exploited to steal credentials and sensitive data. Cisco's internal security teams were able to contain the initial intrusion, but the scope of the breach appears to have affected multiple systems, including developer workstations and lab infrastructure.
The use of CI/CD tools as an entry point confirms a broader trend: attacks are shifting from end applications to the development pipelines themselves, where trust levels are higher and controls are often less stringent.
See also: Axios Supply Chain Attack: Malicious versions distribute RAT
Theft of keys and access to cloud infrastructures
During the attack, multiple Amazon Web Services were reported as exposed. These credentials were used to perform unauthorized actions on a limited number of Cisco accounts. The company immediately isolated the affected systems, reconfigured infrastructure, and performed a mass rotation of credentialsin an attempt to mitigate the risk of further exploitation.
The leakage of cloud credentials is considered particularly critical, as it can lead not only to data loss but also to the abuse of computing resources or the installation of backdoors.

Massive leak of repositories and AI projects
One of the most disturbing aspects of the case is that more than 300 GitHub repositories were allegedly cloned. These include projects related to artificial intelligence, such as AI assistants and defense solutions, as well as products that have not yet been released.
Even more serious is the fact that some of the data belongs to corporate customers, including banking organizations, BPO companies, and U.S. government agencies. This intensifies the potential legal and operational implications for Cisco.
See also: Beware! Malicious ads target Mac users
Multiple attackers and an evolving threat
Sources report that the attack involved more than one threat actor, with varying levels of activity. This suggests either a coordinated operation or exploitation of the same vulnerability by different groups.
The complexity of such attacks makes it difficult to fully assess the damage, while also increasing recovery time.
The attack on Trivy's supply chain
The root of the problem lies in the Trivy, where attackers managed to infect the project's GitHub pipeline. Through it, they distributed credential- stealing, which was integrated into official releases and automated processes.
This particular attack opened the door for to be stolen credentials from organizations using the tool, potentially impacting thousands of environments worldwide. It is a prime example of how dangerous attacks on the software supply chain can become.

TeamPCP in the spotlight
Security researchers have linked the campaign to the TeamPCP, known for using the infostealer “TeamPCP Cloud Stealer.” The group has previously targeted developer platforms such as GitHub, PyPI, NPM, and Docker, seeking access to sensitive data and development pipelines.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Russian CTRL Toolkit: New malware steals passwords and data
At the same time, attacks have been recorded on packages such as LiteLLM and projects such as Checkmarx KICS, where similar malware, affecting tens of thousands of systems.
The broader message for the industry
The Cisco incident highlights a critical reality: security is no longer limited to end-to-end applications, but extends to every stage of development. Supply chain attacks are now one of the most dangerous types of cyberthreats.
For businesses, this means an increased need for controls on third-party tools, continuous monitoring of pipelines, and adoption of zero trust practices. In an ecosystem where code is constantly shared and reused, even a small breach can have large-scale ripple effects.
Source: www.bleepingcomputer.com
