KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack
CYBERSECURITY FEATURED ANALYSIS

KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack

BY

Benjamin Read

SOURCE

Wiz Blog | RSS feed

DATE

READ

1 min read

Checkmarx KICS scanner is the latest victim of a credential-stealing supply chain attack by TeamPCP. Between 12:58–16:50 UTC on March 23, 35 tags were hijacked. Learn how to audit your workflows, identify malicious …

Checkmarx KICS scanner is the latest victim of a credential-stealing supply chain attack by TeamPCP. Between 12:58–16:50 UTC on March 23, 35 tags were hijacked. Learn how to audit your workflows, identify malicious activity, and secure your GitHub Actions.