CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6210

As cited

Copy frozen at (site build).

threat intel

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft

Researchers analyzed two supply chain incidents in late April targeting Checkmarx KICS and elementary-data, both attributed to a threat actor known as TeamPCP. The attacker exploited continuous integration and continuous deployment (CI/CD) and release workflows to steal credentials at scale across compromised projects.

Why it matters: Development teams and organizations using Checkmarx KICS or elementary-data in their CI/CD pipelines need to audit credential exposure and rotate any secrets that may have been compromised during these incidents; this demonstrates a coordinated supply chain campaign targeting build and release infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary