TeamPCP Compromises Checkmarx KICS and VS Code Plugins in Supply Chain Attack

TeamPCP Compromises Checkmarx KICS and VS Code Plugins in Supply Chain Attack

First seen 24 Mar 2026, 22:18 UTC WizDarkreading 69.0

Article Content

Browse articles
ThreatCluster

On March 23, 2026, the KICS GitHub Action, developed by Checkmarx, was compromised by the threat actor TeamPCP, who injected credential-stealing malware. This attack followed a similar incident involving the Trivy open source security scanner, also targeted by TeamPCP. The KICS GitHub Action was available for a four-hour window during which any users pinning to compromised tags were affected. Concurrently, malicious versions of Checkmarx's VS Code plugins were published on the OpenVSX registry. The malware allows attackers to steal sensitive credentials, including SSH keys and API tokens. GitGuardian reported that the campaign extended to the PyPI software registry, affecting Litellm packages. The KICS GitHub Action was taken down shortly after the incident was reported, and the repository was reinstated later the same day. Security experts emphasize the need for organizations to maintain real-time inventories of compromised secrets to mitigate risks from such supply chain attacks.

Key Points: • TeamPCP compromised Checkmarx's KICS GitHub Action and VS Code plugins. • Malware injected allows for extensive credential theft, impacting multiple systems. • Organizations must maintain real-time inventories of secrets to mitigate risks.

Timeline

2026-03-23
KICS GitHub Action compromised with malware by TeamPCP.
2026-03-23
Malicious Checkmarx VS Code plugins published on OpenVSX.
2026-03-23
KICS GitHub Action repository taken down after user report.
2026-03-23
KICS GitHub Action repository reinstated after issue resolution.
2026-03-23
GitGuardian reports extension of attack to Litellm packages on PyPI.