Cisco
Incident posture
Timeline
Summary
Cisco experienced a breach after attackers leveraged stolen credentials from the Trivy supply chain compromise to inject a malicious GitHub Action plugin into its development environment, enabling the theft of credentials and data from build systems and dozens of workstations. The intrusion resulted in the exfiltration of AWS keys that were used for unauthorized activity in a limited set of the company's cloud accounts, the cloning of more than three hundred GitHub repositories containing source code for AI‑focused products such as AI Assistants and AI Defense as well as unreleased tools, and the exposure of portions of those repositories belonging to corporate customers including banks, business process outsourcers and U.S. government agencies. The company responded by isolating affected systems, reimaging them and initiating broad credential rotation, while noting potential fallout from related LiteLLM and Checkmarx supply chain incidents involving multiple threat actors.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The breach began when threat actors exploited the Trivy vulnerability scanner supply chain attack, which had compromised the project's GitHub pipeline to distribute credential‑stealing malware through official releases and GitHub Actions. Using the stolen credentials from that campaign, the attackers deployed a malicious GitHub Action plugin inside Cisco's internal development environment. This plugin allowed them to harvest credentials and data from Cisco's build and development systems, affecting dozens of developer and lab workstations. As part of the same operation, multiple AWS keys were exfiltrated and later used to carry out unauthorized activities in a small number of Cisco AWS accounts. The initial intrusion was eventually contained by Cisco's security teams.
During the incident, more than 300 GitHub repositories were cloned, including source code for Cisco's AI‑powered offerings such as AI Assistants, AI Defense and several unreleased products. A portion of the cloned repositories was identified as belonging to corporate customers, specifically banks, business process outsourcing firms and U.S. government agencies. Multiple sources indicated that more than one threat actor participated in the compromise of Cisco's CI/CD pipelines and AWS accounts, with each actor exhibiting different levels of activity. Cisco reported that the stolen data included both internal proprietary code and customer‑provided source material.
Cisco's Unified Intelligence Center, CSIRT and EOC teams managed to contain the breach and began isolating the affected systems. The company started reimaging the compromised workstations and initiated a wide‑scale credential rotation across its environment. While the immediate breach was halted, Cisco warned that it expects continued fallout from the follow‑on LiteLLM and Checkmarx supply chain attacks that are linked to the same threat group. Security researchers have connected the Trivy, LiteLLM and Checkmarx compromises to the TeamPCP threat actor, which uses its self‑titled 'TeamPCP Cloud Stealer' infostealer in a series of supply chain offensives targeting GitHub, PyPi, NPM and Docker ecosystems. BleepingComputer reached out to Cisco for comment but did not receive a response to its inquiries.
Sources
Sources available to members: 1 source.