Threats & Adversaries · Supply Chain

TeamPCP Uses Stolen CI Credentials to Compromise Checkmarx Actions

TeamPCP compromised two Checkmarx GitHub Actions workflows using credentials stolen in the March 19 Trivy breach (CVE-2026-33634). The actor exfiltrated CI secrets to a vendor-typo domain and created a 'docs-tpcp' repository to stage stolen data as a backup.

2 sources · Mar 24

CVE-2026-33634

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 9

Timeline

Sources

Part of the PlainSec briefing for 2026-03-25

Every edition of this story: TeamPCP Uses Stolen CI Credentials to Compromise Checkmarx Actions

More from today