TeamPCP Steals CI Secrets from Checkmarx GitHub Actions

TeamPCP used credentials from the March 19 Trivy breach (CVE-2026-33634) to access Checkmarx GitHub Actions and exfiltrate CI secrets. They sent secrets to a vendor-typo domain and created a 'docs-tpcp' repo to stage stolen data, raising supply-chain risk.

Part of the PlainSec briefing for 2026-03-26

Sources