Analysis
The build cache is mutable resolution between runs: how a low-privilege context poisons a cache a privileged workflow restores.
Daniel Malvaceda · Jun 20, 2026 · 18 min read
Analysis PyPI python
TeamPCP looted LiteLLM in 46 minutes. A patient attacker uses the same proxy position for far more. Three surfaces your AI security posture isn't covering.
Daniel Malvaceda · May 31, 2026 · 18 min read
Analysis
The structural gap between what a pipeline declares and what it executes, and what hash pinning actually fixes.
Daniel Malvaceda · Apr 16, 2026 · 14 min read
Incident Critical npm PyPI openvsix
TeamPCP's endgame: LiteLLM's PyPI wheel backdoored post-build, .pth system-wide persistence, and why AI gateways are a new class of supply chain target.
Daniel Malvaceda · Apr 1, 2026 · 27 min read
Incident Critical GitHub Actions docker-hub
How a two-minute GitHub PR gave TeamPCP 18 days of silent access to Trivy's CI: Pwn Request, non-atomic rotation, and 82 poisoned Actions tags.
Daniel Malvaceda · Mar 27, 2026 · 21 min read