SANS Stormcast: Daily Cyber Security News · Johannes Ullrich

SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More

March 25, 2026·12 min·1 clip
North Korean IT workers in the U.S. are using IP KVMs as undetectable remote access tools.
Ulrich opens with a diary entry on IP KVM detection, motivated by coverage of North Korean IT workers using hardware KVM devices to remotely operate laptops sent to U.S. addresses. KVMs operate below the OS level and require no installed software, making them harder to detect. He tested two devices: the Sipeed Nano KVM, whose USB descriptor explicitly identifies the device by name, and the Pi KVM, which uses more generic USB strings but can be identified via its HDMI EDID monitor identifier. Ulrich notes that attackers can alter these strings but considers them worthwhile detection signals. The main story covers Team PCP, a threat actor tracked by Flare since approximately December. In late February, their automated bot HackerBotClaus scanned GitHub CI/CD workflows for exposed credentials and found a privileged access token from Aqua Security, a company that sells supply chain security products. Using that token, the bot pushed malicious artifacts into Trivy, Aqua's open-source vulnerability scanner and its related Visual Studio Code extension. Aqua Security discovered and remediated the compromise, publishing an advisory and rotating credentials. However, Team PCP returned on March 19th and replaced an existing Trivy binary release rather than releasing a new version — a tactic that defeated version-tag pinning since the tag pointed to the same now-malicious binary. The payload was a standard info stealer harvesting SSH keys, cloud tokens, and other secrets. Aqua Security caught this within hours and published details on March 20th and 22nd, but a day later acknowledged the attacker may still have some access. LiteLLM announced it was also affected, turning the Trivy compromise into a multi-level supply chain attack because LiteLLM holds credentials for multiple LLM providers. Ulrich explains LiteLLM's role as a centralized proxy routing prompts across AI providers, making its credential store a high-value target. The checkmarks open-source projects KICS and related VS Code extensions were also replaced using the same technique, likely using credentials stolen from Trivy. Sysdig, who assisted with incident response, suggests checkmarks may have been compromised via its use of Trivy. Ulrich closes with a newly identified Kubernetes wiper attributed to Team PCP by Aqua Security, targeting systems with Iranian time zones or Farsi locales, then spreading via SSH. He recommends pinning dependencies by git hash rather than version tags and emphasizes that LiteLLM and checkmarks are likely just visible examples of a broader set of compromised repositories given Trivy's wide usage.
Listen to the show on