logo

KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack

ID: 95a84d21-2714-5f04-8f5c-e2bd648db3e2

STIX ID: report--95a84d21-2714-5f04-8f5c-e2bd648db3e2

Feed Name: Wiz Blog

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-05-01

...
...

The KICS GitHub Action was compromised on March 23 by the threat actor TeamPCP, who injected credential-stealing malware into multiple released tags using a compromised service account; the malware used a new C2 domain (checkmarx.zone), created a fallback repo (docs-tpcp) for exfiltration, and added Kubernetes persistence. Organizations using kics-github-action should audit workflows, check for repository exfiltration artifacts, and follow hardening guidance to remediate potential exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.