As cited
Copy frozen at (site build).
threat intel
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft
Researchers analyzed two supply chain incidents in late April targeting Checkmarx KICS and elementary-data, both attributed to a threat actor known as TeamPCP. The attacker exploited continuous integration and continuous deployment (CI/CD) and release workflows to steal credentials at scale across compromised projects.
Why it matters: Development teams and organizations using Checkmarx KICS or elementary-data in their CI/CD pipelines need to audit credential exposure and rotate any secrets that may have been compromised during these incidents; this demonstrates a coordinated supply chain campaign targeting build and release infrastructure.
- Source published
- First seen by Cybersecurity Tracker