CVE-2026-33634
Known exploited · CISA KEV
CISA federal remediation date Apr 9
Threats & Adversaries · Supply Chain
TeamPCP used credentials from the March 19 Trivy breach (CVE-2026-33634) to access Checkmarx GitHub Actions and exfiltrate CI secrets. They sent secrets to a vendor-typo domain and created a 'docs-tpcp' repo to stage stolen data, raising supply-chain risk.
2 sources · Mar 24
Known exploited · CISA KEV
CISA federal remediation date Apr 9
The Hacker News
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
TeamPCP compromised 2 GitHub Actions post-March 19, 2026 breach, enabling credential theft and supply chain attacks.
originalWiz Research
KICS GitHub Action Compromised: TeamPCP Supply Chain Attack | Wiz Blog
Checkmarx KICS Github Action hijacked by TeamPCP.
originalPart of the PlainSec briefing for 2026-03-26
Every edition of this story: TeamPCP Steals CI Secrets from Checkmarx GitHub Actions