logo

TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike

ID: c7b3dc5d-4ed8-5278-87e2-d3cd9911624e

STIX ID: report--c7b3dc5d-4ed8-5278-87e2-d3cd9911624e

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers discovered a supply-chain attack in which official Checkmarx Docker images and VS Code extensions were hijacked to deploy a credential-stealing malware (mcpAddon.js) that exfiltrates secrets by creating deceptive GitHub repositories and injecting malicious GitHub Actions workflows; the campaign, attributed to 'TeamPCP', also attempts npm package takeovers to propagate and compromises developer and cloud credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.