KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack
wiz.io | incident | #supply-chain | #github-actions | #incident | #checkmarx | #teampcp | #kics | #openvsx
Summary
TeamPCP hijacked the Checkmarx KICS GitHub Action on March 23, serving credential-stealing malware from 35 tags; OpenVSX extensions were hit too. Audit for docs-tpcp repos and checkmarx.zone C2.
- Published
- Collected
Skip to content