Darkreading TeamPCP Compromises Checkmarx KICS and VS Code Plugins in Supply Chain Attack
Article Content
- •TeamPCP compromised Checkmarx's KICS GitHub Action and VS Code plugins.
- •Malware injected allows for extensive credential theft, impacting multiple systems.
- •Organizations must maintain real-time inventories of secrets to mitigate risks.
On March 23, 2026, the KICS GitHub Action, developed by Checkmarx, was compromised by the threat actor TeamPCP, who injected credential-stealing malware. This attack followed a similar incident involving the Trivy open source security scanner, also targeted by TeamPCP. The KICS GitHub Action was available for a four-hour window during which any users pinning to compromised tags were affected. Concurrently, malicious versions of Checkmarx's VS Code plugins were published on the OpenVSX registry. The malware allows attackers to steal sensitive credentials, including SSH keys and API tokens. GitGuardian reported that the campaign extended to the PyPI software registry, affecting Litellm packages. The KICS GitHub Action was taken down shortly after the incident was reported, and the repository was reinstated later the same day. Security experts emphasize the need for organizations to maintain real-time inventories of compromised secrets to mitigate risks from such supply chain attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…