TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions
ID: 1aed2991-76f4-51da-be5e-d3d7f86681bf
STIX ID: report--1aed2991-76f4-51da-be5e-d3d7f86681bf
Feed Name: Sysdig Blog
**Executive Summary:** The Sysdig Threat Research Team observed TeamPCP compromise multiple GitHub Actions (including aquasecurity/trivy-action and Checkmarx/ast-github-action) to deploy an identical credential-stealing payload that harvested GitHub tokens and cloud IMDS credentials and exfiltrated them as an encrypted archive (tpcp.tar.gz) to vendor-typosquat domains (scan.aquasecurtiy.org, checkmarx.zone); the report includes IOCs, process/network artifacts, detection mappings (Falco/Sysdig Secure rules), and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
