CVE-2026-33634
Known exploited · CISA KEV
CISA federal remediation date Apr 9
Threats · 168 days ago
TeamPCP overwritten release tags on the Checkmarx ast-github-action and committed credential-stealing composite actions that call the legitimate action. The compromised Checkmarx package and a separate LiteLLM PyPI compromise enabled harvesting of cloud credentials, SSH keys, Kubernetes configs and build/process secrets. Researchers observed TeamPCP validating, encrypting and staging those secrets on attacker-controlled domains for later use. CISA added CVE-2026-33634 to the KEV and public detection tooling for this campaign and the LiteLLM PyPI compromise is detectable with available tools.
Known exploited · CISA KEV
CISA federal remediation date Apr 9
2 sources covering this story
TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets
TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ and Vect ransomware gangs
TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, Author: Kenneth Hartman
TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, Author: Kenneth Hartman
Part of the PlainSec briefing for 2026-04-01