logo

TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions

ID: 1aed2991-76f4-51da-be5e-d3d7f86681bf

STIX ID: report--1aed2991-76f4-51da-be5e-d3d7f86681bf

Feed Name: Sysdig Blog

Threat Score
90/100

Date Published: 2026-03-23

Date Updated: 2026-05-01

...
...

**Executive Summary:** The Sysdig Threat Research Team observed TeamPCP compromise multiple GitHub Actions (including aquasecurity/trivy-action and Checkmarx/ast-github-action) to deploy an identical credential-stealing payload that harvested GitHub tokens and cloud IMDS credentials and exfiltrated them as an encrypted archive (tpcp.tar.gz) to vendor-typosquat domains (scan.aquasecurtiy.org, checkmarx.zone); the report includes IOCs, process/network artifacts, detection mappings (Falco/Sysdig Secure rules), and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.