KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack
ID: 95a84d21-2714-5f04-8f5c-e2bd648db3e2
STIX ID: report--95a84d21-2714-5f04-8f5c-e2bd648db3e2
Feed Name: Wiz Blog
The KICS GitHub Action was compromised on March 23 by the threat actor TeamPCP, who injected credential-stealing malware into multiple released tags using a compromised service account; the malware used a new C2 domain (checkmarx.zone), created a fallback repo (docs-tpcp) for exfiltration, and added Kubernetes persistence. Organizations using kics-github-action should audit workflows, check for repository exfiltration artifacts, and follow hardening guidance to remediate potential exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
