PULSE NAME
Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions
WHITE TeamPCP AlienVault 2026-03-24 Modified: 2026-03-24
3
IOCs
LOW VOLUME
A threat actor known as TeamPCP expanded its supply chain attack from Aqua Security's Trivy to Checkmarx's AST GitHub Action. The attack, which began on March 19, 2026, involved injecting a credential-stealing payload into CI/CD pipelines across thousands of repositories. The malicious code harvested secrets from runner memory, queried cloud metadata, and exfiltrated encrypted data to typosquat domains. The Checkmarx compromise occurred approximately four days after the initial Trivy incident, using identical techniques but targeting a different action. This cascading effect demonstrates how compromised actions can be used to harvest credentials and compromise additional dependencies. Runtime detection proved effective in identifying the attack pattern across both waves, as the underlying behavior remained consistent despite changes in the delivery mechanism.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
TeamPCP Cloud stealer
Indicators of Compromise (3)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain aquasecurtiy.org 2026-03-24
domain checkmarx.zone 2026-03-24
hostname scan.aquasecurtiy.org 2026-03-24