Threats & Adversaries · Supply Chain

All Checkmarx Action Tags Overwritten in TeamPCP Supply-Chain Compromise

TeamPCP overwrote all 91 published tags of the Checkmarx ast-github-action and committed credential-stealing composite actions that then invoke the legitimate action. CISA added CVE-2026-33634 to the KEV, and detection tooling for this campaign and the LiteLLM PyPI compromise is available.

2 sources · Apr 1

CVE-2026-33634

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 9

Timeline

Sources

Part of the PlainSec briefing for 2026-03-27

Every edition of this story: All Checkmarx Action Tags Overwritten in TeamPCP Supply-Chain Compromise

More from today