Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack

Summary

TeamPCP hijacked the Checkmarx KICS GitHub Action on March 23, serving credential-stealing malware from 35 tags; OpenVSX extensions were hit too. Audit for docs-tpcp repos and checkmarx.zone C2.
Published
Collected

original ↗

Related coverage

back