← Back to Feed
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft
May 13, 2026 · Trend Micro · Severity: LOW
Our research examines the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused trusted CI/CD and release workflows to steal credentials at scale.
Key Takeaways
- Trend Micro analyzed the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign.
- The actor abused trusted CI/CD and release workflows to steal credentials at scale in both cases.
- Organizations should audit CI/CD pipeline trust boundaries and third-party release workflows, since attackers increasingly target them for credential theft.