logo

TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials

ID: 939c3a45-5e18-5082-820a-24478ef6d788

STIX ID: report--939c3a45-5e18-5082-820a-24478ef6d788

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Two GitHub Actions workflows and associated OpenVSX extensions were compromised by a credential‑stealing campaign attributed to the TeamPCP group, which also carried out the Trivy supply‑chain attack (CVE-2026-33634). The 'TeamPCP Cloud stealer' harvests CI and cloud credentials (GitHub tokens, AWS/GCP/Azure, SSH keys, Docker/Kubernetes, wallets, webhooks), exfiltrates encrypted archives to checkmarx.zone (tpcp.tar.gz), and implements fallback staging (creating repos like docs-tpcp). The campaign included trojanized VSIX packages, malicious Docker images, and persistence on endpoints, enabling cascading repository and cloud compromises and posing a severe supply‑chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.