TeamPCP overwritten release tags on the Checkmarx ast-github-action and committed credential-stealing composite actions that call the legitimate action. The compromised Checkmarx package and a separate LiteLLM PyPI compromise enabled harvesting of cloud credentials, SSH keys, Kubernetes configs and build/process secrets. Researchers observed TeamPCP validating, encrypting and staging those secrets on attacker-controlled domains for later use. CISA added CVE-2026-33634 to the KEV and public detection tooling for this campaign and the LiteLLM PyPI compromise is detectable with available tools.
Part of the PlainSec briefing for 2026-04-01