Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit
2026-03-25T02:51:41Z•29a7c95f9e46cf88dfe9b3e6130df6d3d45b2f14608b5851afff721acf0c79d4
CI/CD-secretsCheckmarx-KICSClaudeDarkSwordGitHubGlassWormLiteLLMOpen-VSXOpenClawOracle-Fusion-MiddlewareRCESnappyClientTeamPCPTrivyVS-Code-extensioncredential-theftiOS-exploitinfostealermalicious-packagespoisoned-packagesprompt-injectionransomwaresoftware-supply-chainsupply-chain-attackvulnerability
What happened
A string of DarkReading reports describes a widening wave of software‑supply‑chain and AI‑assisted attacks. Threat actor(s) likely tied to 'TeamPCP' have targeted open‑source development tooling (Trivy, Checkmarx KICS, VS Code plug‑ins) and the LiteLLM library; Trivy was abused to deploy an infostealer into CI/CD pipelines to harvest cloud credentials, SSH keys and tokens. Separate campaigns delivered trojans via a GitHub 'OpenClaw Deployer' repo and over 300 poisoned packages; GlassWorm malicious extensions were found in Open VSX. The news feed also highlights high‑impact vulnerabilities and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 29a7c95f9e46cf88dfe9b3e6130df6d3d45b2f14608b5851afff721acf0c79d4
- Enrichment time
- 2026-03-25T02:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.