Federal Analysis
Threat Actors Compromise AI Supply Chain Tools
March 25, 2026
In March 2026, the TeamPCP threat actor executed sophisticated supply chain attacks compromising critical AI infrastructure tools including Aqua's Trivy vulnerability scanner, Checkmarx's AST GitHub Actions, and the open-source Python package LiteLLM. These attacks involved the release of malicious software versions that stole credentials and embedded information-stealing malware, exposing significant vulnerabilities in AI and software supply chains. This series of incidents underscores the urgent need for government agencies and contractors to treat AI infrastructure as critical enterprise infrastructure, implement enhanced security architectures, and comply with evolving regulatory requirements to safeguard procurement and operational environments.
- Agencies relying on AI development and security tools must reassess supply chain risk management and incorporate stricter vetting and monitoring of third-party software components.
- Procurement professionals should prioritize vendors demonstrating robust supply chain security practices and consider contractual requirements for transparency and incident response capabilities.
- Contractors involved in AI and software development should evaluate their dependency management and update policies to mitigate risks from compromised open-source packages.
- This situation highlights the growing importance of integrating cybersecurity measures into AI infrastructure procurement and the potential for regulatory frameworks to mandate such protections.
Your vulnerability scanner can be a vulnerability. Your dependency checker can be the compromised dependency. The tools meant to protect the supply chain are themselves part of the supply chain.
— Kevin McGahey
Hackers published a malicious scanner release and replaced tags to point to information-stealer malware.
— Ionut Arghire
Agencies
National Security Agency, European Union
Vendors
Aqua Security, Aqua, Trivy, LiteLLM, Checkmarx
Sources
- Trivy Archives - SecurityWeek · SecurityWeek · Mar 23
- The AI Supply Chain Is Now Critical Infrastructure: Lessons from the TeamPCP Campaign That Hit Trivy, Checkmarx, and LiteLLM · DreamFactory Blog · Mar 25
- The LiteLLM Supply Chain Attack: A Complete Technical Breakdown of What Happened, Who Is Affected, and What Comes Next · DreamFactory Blog · Mar 25