Threats & Adversaries · Supply Chain
All Checkmarx Action Tags Overwritten in TeamPCP Supply-Chain Compromise TeamPCP overwrote all 91 published tags of the Checkmarx ast-github-action and committed credential-stealing composite actions that then invoke the legitimate action. CISA added CVE-2026-33634 to the KEV, and detection tooling for this campaign and the LiteLLM PyPI compromise is available.
2 sources · Apr 1
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Apr 9
Timeline Sources Apr 1 Infosecurity Magazine
TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets
TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ and Vect ransomware gangs
original Mar 30 SANS ISC
TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released
TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, Author: Kenneth Hartman
original Mar 28 SANS ISC
TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours
TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, Author: Kenneth Hartman
original Part of the PlainSec briefing for 2026-03-27
Every edition of this story: All Checkmarx Action Tags Overwritten in TeamPCP Supply-Chain Compromise
More from today
Threats & Adversaries · Supply Chain
All Checkmarx Action Tags Overwritten in TeamPCP Supply-Chain Compromise TeamPCP overwrote all 91 published tags of the Checkmarx ast-github-action and committed credential-stealing composite actions that then invoke the legitimate action. CISA added CVE-2026-33634 to the KEV, and detection tooling for this campaign and the LiteLLM PyPI compromise is available.
2 sources · Apr 1
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Apr 9
Timeline Sources Apr 1 Infosecurity Magazine
TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets
TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ and Vect ransomware gangs
original Mar 30 SANS ISC
TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released
TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, Author: Kenneth Hartman
original Mar 28 SANS ISC
TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours
TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, Author: Kenneth Hartman
original Part of the PlainSec briefing for 2026-03-27
Every edition of this story: All Checkmarx Action Tags Overwritten in TeamPCP Supply-Chain Compromise
More from today