
TeamPCP, the same cybercriminals behind the Trivy supply chain attack, have compromised two more GitHub Actions workflows to steal credentials.
These workflows, both from the supply chain security firm Checkmarx, are:
Sysdig, a cloud security company, noticed the identical credential-stealing malware used in TeamPCP’s attacks against Aqua Security’s Trivy scanner and its GitHub Actions, roughly four days after the March 19, 2026 breach. The Trivy supply chain issue is tracked as CVE-2026-33634 (CVSS score: 9.4).
“This implies that the stolen credentials from the Trivy attack were used to infect more actions in affected repositories,” Sysdig stated.
The “TeamPCP Cloud stealer” aims to steal credentials and secrets such as SSH keys, Git credentials, AWS, Google Cloud, Microsoft Azure, Kubernetes, Docker, .env files, database credentials, and VPN information, along with CI/CD configurations, cryptocurrency wallet data, and Slack and Discord webhook URLs.
As with the Trivy incident, the attackers pushed malicious tags and commits with the stealer payload (“setup.sh”). The stolen data is sent to “checkmarx[.]zone” (IP address: 83.142.209[.]11:443) as an encrypted archive called “tpcp.tar.gz”.
A new tactic involves creating a “docs-tpcp” repository using the victim’s GITHUB_TOKEN to store the stolen data if sending it to the server fails. In the Trivy incident, the threat actors used the repository name “tpcp-docs” instead.
“Using vendor-specific, slightly misspelled domains for each infected action is a deliberate trick,” Sysdig explained. “Analysts reviewing CI/CD logs might overlook this traffic to what appears to be the vendor’s legitimate domain.”
The stealer’s main function is to grab credentials from CI runner memory, allowing the attackers to extract GitHub personal access tokens (PATs) and other secrets when a compromised Trivy action runs in a workflow. Worse, if those tokens can write to repositories that use Checkmarx actions, the attacker can exploit them to inject malicious code.
This can lead to a widespread supply chain attack, where a compromised action steals secrets and uses them to compromise other actions.
“The identical payload, encryption, and the ‘tpcp.tar.gz’ naming show that it’s the same actor expanding their attack beyond the initial Trivy compromise,” Sysdig noted. “Code review and dependency scanning failed because the malicious code was injected directly into a trusted action.”
Wiz reports that the attack was carried out by compromising the “cx-plugins-releases” service account, and the attackers also released trojanized versions of the “ast-results” (version 2.53.0) and “cx-dev-assist” Open VSX extensions. The VS Code Marketplace versions are not affected.
After the extension is activated, the malware checks if the victim has credentials for cloud providers like GitHub, AWS, Google Cloud, or Microsoft Azure. If credentials are found, it downloads a second-stage payload from the same domain (“checkmarx[.]zone”).
“The payload tries to execute using npx, bunx, pnpx, or yarn dlx, covering major JavaScript package managers,” Wiz researchers Rami McCarthy, James Haughom, and Benjamin Read said. “The downloaded package is a comprehensive credential stealer. The stolen credentials are encrypted using the same keys as before and sent to ‘checkmarx[.]zone/vsx’ as tpcp.tar.gz.”
“On non-CI systems, the malware achieves persistence via a systemd user service. This script polls https://checkmarx[.]zone/raw every 50 minutes for more payloads, with a kill switch that triggers if the response says ‘youtube’. Currently, the link redirects to The Show Must Go On by Queen.”
To reduce the damage, users should take these steps immediately:
After the initial breach, TeamPCP actors pushed malicious Docker images of Trivy with the same stealer and took over the company’s “aquasec-com” GitHub organization to modify many internal repositories.
They have also targeted Kubernetes clusters with a malicious script that wipes all machines matching the Iranian time zone, showing an increase in the group’s capabilities.
#actions #checkmarx #ci/cd #compromised #credentials #github #hack. #let #news #stolen #teampcp #them. — News
© Bulletproof Servers. All rights reserved.