logo

TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available, (Thu, Mar 26th)

ID: 1d8d5af4-2d4f-5e1f-811d-aababb9b187a

STIX ID: report--1d8d5af4-2d4f-5e1f-811d-aababb9b187a

Feed Name: SANS ISC Diary

Threat Score
90/100

Date Published: 2026-03-26

Date Updated: 2026-04-19

...
...

This update documents the TeamPCP supply-chain campaign that injected credential-stealing malware into Checkmarx's ast-github-action (all 91 tags overwritten) and compromised LiteLLM PyPI releases (malicious versions yanked), confirms active exploitation (CVE-2026-33634 added to CISA KEV), and provides remediation and detection guidance including log searches, version pins, and credential rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.