TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
ID: 939c3a45-5e18-5082-820a-24478ef6d788
STIX ID: report--939c3a45-5e18-5082-820a-24478ef6d788
Feed Name: The Hacker News
Two GitHub Actions workflows and associated OpenVSX extensions were compromised by a credential‑stealing campaign attributed to the TeamPCP group, which also carried out the Trivy supply‑chain attack (CVE-2026-33634). The 'TeamPCP Cloud stealer' harvests CI and cloud credentials (GitHub tokens, AWS/GCP/Azure, SSH keys, Docker/Kubernetes, wallets, webhooks), exfiltrates encrypted archives to checkmarx.zone (tpcp.tar.gz), and implements fallback staging (creating repos like docs-tpcp). The campaign included trojanized VSIX packages, malicious Docker images, and persistence on endpoints, enabling cascading repository and cloud compromises and posing a severe supply‑chain risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
