Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit
ID: 632da508-fbbb-53b2-b268-4407e0ff350f
STIX ID: report--632da508-fbbb-53b2-b268-4407e0ff350f
Feed Name: Dark Reading
This report details a widespread supply-chain campaign attributed to the threat actor TeamPCP that poisoned multiple open-source developer tools and registries—Trivy, KICS GitHub Action, OpenVSX VS Code plugins, and LiteLLM on PyPI—by publishing malicious versions containing an infostealer. The compromised artifacts targeted CI/CD pipelines and developer environments to exfiltrate secrets (SSH keys, cloud credentials, API tokens, Docker configs, crypto wallet info), with active distribution windows confirmed and common IoCs linking the incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
