Post

HN
Hacker News (Newest)

SmokedMeat: A Red Team Tool to Hack Your Pipelines First

Franรงois is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

TL;DR : In March 2026, TeamPCP unleashed mayhem on the software supply chain: compromising Trivy, LiteLLM, KICS, Telnyx, and dozens of npm packages, proving that CI/CD pipelines are the softest target. Today weโ€™re open-sourcing SmokedMeat , the first red team framework for build pipelines (i.e. CI/CD), so defenders can finally see the full kill chain for themselves.

In December 2025, we warned that threat actors were weaponizing defensive research as an offensive playbook , citing poutine and our LOTP catalog on BreachForums before hitting real targets. The era of awareness ended, and the era of exploitation began.

A few months later, TeamPCP proved us right . MegaGame10418 stole the aqua-bot PAT from Trivyโ€™s CI pipeline using the exact Pwn Request weakness poutine had flagged months earlier. The campaign cascaded into LiteLLM , KICS, Telnyx, and dozens of npm packages: 70+ private repos exposed, 230+ CI secrets at risk.

poutine tells you where your pipelines are vulnerable. Our articles tell you what happens when someone exploits them. But defenders still canโ€™t see the kill chain end-to-end, and that gap is what lets findings get deprioritized while TeamPCP turns a workflow injection into your AWS production credentials in under 60 seconds .

SmokedMeat: like Metasploit, but for CI/CD