As cited
Copy frozen at (site build).
KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack
Checkmarx's KICS GitHub Action was compromised during a supply chain attack by TeamPCP on March 23, with attackers hijacking 35 tags over approximately four hours. The incident appears to involve credential theft and highlights the vulnerability of popular development tools in continuous integration and continuous deployment (CI/CD) pipelines. Organizations using this GitHub Action should audit their workflows for malicious activity and take corrective measures.
Why it matters: Development teams relying on KICS GitHub Action for infrastructure as code scanning may have exposed credentials or injected malicious code into their CI/CD pipelines; immediate audit and remediation of affected workflows is essential.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack
Checkmarx's KICS GitHub Action was compromised during a supply chain attack by TeamPCP on March 23, with attackers hijacking 35 tags over approximately four hours. The incident appears to involve credential theft and highlights the vulnerability of popular development tools in continuous integration and continuous deployment (CI/CD) pipelines. Organizations using this GitHub Action should audit their workflows for malicious activity and take corrective measures.
Why it matters: Development teams relying on KICS GitHub Action for infrastructure as code scanning may have exposed credentials or injected malicious code into their CI/CD pipelines; immediate audit and remediation of affected workflows is essential.
- Source published
- First seen by Cybersecurity Tracker