CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1327

As cited

Copy frozen at (site build).

KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack

Checkmarx's KICS GitHub Action was compromised during a supply chain attack by TeamPCP on March 23, with attackers hijacking 35 tags over approximately four hours. The incident appears to involve credential theft and highlights the vulnerability of popular development tools in continuous integration and continuous deployment (CI/CD) pipelines. Organizations using this GitHub Action should audit their workflows for malicious activity and take corrective measures.

Why it matters: Development teams relying on KICS GitHub Action for infrastructure as code scanning may have exposed credentials or injected malicious code into their CI/CD pipelines; immediate audit and remediation of affected workflows is essential.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack

Checkmarx's KICS GitHub Action was compromised during a supply chain attack by TeamPCP on March 23, with attackers hijacking 35 tags over approximately four hours. The incident appears to involve credential theft and highlights the vulnerability of popular development tools in continuous integration and continuous deployment (CI/CD) pipelines. Organizations using this GitHub Action should audit their workflows for malicious activity and take corrective measures.

Why it matters: Development teams relying on KICS GitHub Action for infrastructure as code scanning may have exposed credentials or injected malicious code into their CI/CD pipelines; immediate audit and remediation of affected workflows is essential.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary