← Back to Feed

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft

May 13, 2026 · Trend Micro · Severity: LOW

Our research examines the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused trusted CI/CD and release workflows to steal credentials at scale.

Key Takeaways

  • Trend Micro analyzed the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign.
  • The actor abused trusted CI/CD and release workflows to steal credentials at scale in both cases.
  • Organizations should audit CI/CD pipeline trust boundaries and third-party release workflows, since attackers increasingly target them for credential theft.
☕ Buy a Coffee