logo

TeamPCP’s Checkmarx GitHub Actions Attack: What You Need to Know

ID: 5cf17a8c-f688-5d04-a442-0a5f10751f1b

STIX ID: report--5cf17a8c-f688-5d04-a442-0a5f10751f1b

Feed Name: SOCRadar Blog

Threat Score
92/100

Date Published: 2026-03-25

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

The report details a high-impact, multi-stage supply chain campaign by TeamPCP that began with a poisoned Trivy release and expanded to compromise Checkmarx GitHub Actions, developer tooling (OpenVSX extensions), package ecosystems (npm, PyPI), and container registries; the adversary harvested CI/CD and cloud credentials (packaged as tpcp.tar.gz), used resilient exfiltration (typosquat domains, cloud tunnels, and fallback GitHub repos), deployed self-propagating packages (CanisterWorm), and included destructive, Iran-targeted wiper capabilities—providing IoCs, recommended mitigations (rotate secrets, pin SHAs, move to OIDC, egress filtering), and mapped MITRE ATT&CK techniques for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.