TeamPCP Supply Chain Attack: Trivy, KICS, and Bitwarden CLI Backdoors — Full Analysis
Full forensic analysis of the TeamPCP campaign: tag poisoning and entrypoint backdoors injected into Trivy, KICS, and Bitwarden CLI.
← Back to the June 4 Security Roundup
Overview
Between February and April 2026, a threat actor tracked as TeamPCP executed a coordinated supply chain campaign targeting widely-used developer and security tools: Aqua Security's Trivy vulnerability scanner, the Checkmarx KICS infrastructure-as-code scanner, and the Bitwarden CLI npm package. The attackers leveraged incomplete credential rotation in the Trivy repository to gain initial access, then used stolen developer secrets to pivot to KICS and Bitwarden. Over 334 developers pulled the backdoored Bitwarden CLI within 90 minutes of publication; downstream impact included credential theft affecting OpenAI and Vercel developer environments.
Timeline
- Feb 2026: TeamPCP exploits incomplete credential rotation in Aqua Security's Trivy GitHub repository.
- Mar 16, 2026: Malicious code injected into Trivy — credential-stealing payload harvests cloud credentials, SSH keys, Kubernetes config files, and developer secrets from CI/CD runners.
- Mar 23, 2026: Stolen developer credentials from Trivy used to push malicious artifacts to the Checkmarx KICS repository (Docker image
checkmarx/kics:v2.1.4-tainted). KICS Go binary modified with unauthorized telemetry + exfiltration routine encrypting scan reports to attacker C2. - Apr 22, 2026: Trojanized Bitwarden CLI v2026.4.0 published to npm. JavaScript payload fetches additional stage from attacker-controlled CDN and exfiltrates password vault contents + local secrets. Package pulled after ~90 minutes; 334 downloads confirmed.
Malware Behavior
All three implants share the same C2 domain (telemetry-cdn[.]dev) and use an HTTPS POST with a custom header (X-Client-ID) to exfiltrate stolen data. The KICS binary modification adds a goroutine that, after each scan, AES-256-GCM encrypts the scan report (containing all found IaC misconfigurations and file paths) and POSTs it to the C2. The Bitwarden npm payload targets:
- Bitwarden vault JSON (
~/.config/Bitwarden CLI/data.json) - AWS credential files (
~/.aws/credentials, environment variables) - SSH private keys in
~/.ssh/ - Docker config (
~/.docker/config.json) including registry tokens - Environment variables matching
*TOKEN*,*SECRET*,*KEY*,*PASSWORD*
Affected Package Versions
- Trivy: Any Trivy binary or Docker image pulled between Mar 16–Mar 22, 2026
- Checkmarx KICS:
checkmarx/kics:v2.1.4Docker image (SHA256:a3f9b2c1...) - Bitwarden CLI npm:
@bitwarden/[email protected]
IOCs
- C2 domain:
telemetry-cdn[.]dev(185.220.101[.]47) - DNS queries to
telemetry-cdn[.]devfrom CI/CD systems or developer workstations - Outbound HTTPS POST with header
X-Client-ID: <base64_blob>to185.220.101[.]47 - Bitwarden npm package
@bitwarden/[email protected]inpackage-lock.jsonornode_modules - KICS Docker image digest:
sha256:a3f9b2c1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1
Remediation
# 1. Check if affected packages were used
# Bitwarden CLI
npm ls @bitwarden/cli | grep 2026.4.0
# Check KICS Docker image digest
docker inspect checkmarx/kics:v2.1.4 --format '{{index .RepoDigests 0}}'
# 2. Rotate ALL credentials that were present in environments running the affected tools
# Priority: AWS keys, GCP service account keys, GitHub tokens, NPM tokens
# 3. Revoke and regenerate SSH keys if ~/.ssh/ was accessible during the affected period
# 4. Block C2 domain at DNS/firewall level
# Block: telemetry-cdn[.]dev (185.220.101.47)
echo "0.0.0.0 telemetry-cdn.dev" | sudo tee -a /etc/hosts
# 5. Scan for active C2 connections
netstat -an | grep 185.220.101.47
ss -tp | grep 185.220.101.47
# 6. Update to clean versions:
# Trivy: >= 0.62.0 (post-remediation build)
# KICS: checkmarx/kics:latest (verified clean post Apr 25)
# Bitwarden CLI: @bitwarden/[email protected] or later
npm install -g @bitwarden/cli@latest
← Back to the June 4 Security Roundup