Threats & Adversaries · Supply Chain

TeamPCP Steals CI Secrets from Checkmarx GitHub Actions

TeamPCP used credentials from the March 19 Trivy breach (CVE-2026-33634) to access Checkmarx GitHub Actions and exfiltrate CI secrets. They sent secrets to a vendor-typo domain and created a 'docs-tpcp' repo to stage stolen data, raising supply-chain risk.

2 sources · Mar 24

CVE-2026-33634

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 9

Timeline

Sources

Part of the PlainSec briefing for 2026-03-26

Every edition of this story: TeamPCP Steals CI Secrets from Checkmarx GitHub Actions

More from today