Proprietary ·

Checkmarx tools stole CI secrets

TeamPCP poisoned Checkmarx GitHub Actions and OpenVSX extensions. The payload hunted CI, cloud, SSH, Kubernetes, and developer credentials from trusted scanning tools.

Part of Checkmarx vs TeamPCP campaign

The March Checkmarx incident began in the places developers trust by habit. Malicious OpenVSX extensions appeared early on March 23. Later that day, Checkmarx GitHub Actions tags were altered so CI jobs pulled attacker code as normal scanner setup.

The GitHub Actions payload changed the action startup path and ran setup.sh. It searched runners for environment variables, SSH keys, cloud metadata, Kubernetes tokens, and GitHub Actions process memory. It encrypted the collection, wrote tpcp.tar.gz, and tried to send it to TeamPCP infrastructure, with GitHub release upload as a fallback.

The OpenVSX payload used the IDE instead of CI. Compromised ast-results and cx-dev-assist VSIX files loaded a malicious checker, gated execution on the presence of cloud credentials, fetched a second stage, then used the same credential-stealing grammar. On developer machines it could install a user-level systemd persistence loop.

Checkmarx removed the affected artifacts, deleted older GitHub versions, rotated credentials, and advised users to move to verified releases. The incident is recorded as its own attack because it compromised Checkmarx-controlled distribution channels on March 23, even though the technique and infrastructure tie it to the wider TeamPCP campaign.

Appendix · Affected releases

checkmarx/ast-github-action github actions fixed 2.3.33
  • Checkmarx later identified 2.3.32 and floating main references that resolved during the exposure window as compromised; safe replacement guidance pointed users to v2.3.33 or later.
  • Floating main references that resolved during the March 2026 exposure window were affected.
  • Package coordinates recorded for the affected releases: pkg:github/Checkmarx/ast-github-action@2.3.32.
checkmarx/kics-github-action github actions fixed 2.1.20
  • Third-party reporting described all release tags as poisoned with setup.sh changes; Checkmarx described any floating reference that resolved during the window as affected.
  • All active tags during the March 2026 exposure window were reported affected.
  • Floating main references that resolved during the March 2026 exposure window were affected.
checkmarx.ast-results openvsx
2.53.0
  • Package coordinates recorded for the affected releases: pkg:vscode/checkmarx/ast-results@2.53.0.
checkmarx.cx-dev-assist openvsx
1.7.0
  • Package coordinates recorded for the affected releases: pkg:vscode/checkmarx/cx-dev-assist@1.7.0.

Indicators

  • domaincheckmarx.zone
  • ip83.142.209.11
  • filesetup.sh
  • fileenvironmentAuthChecker.js
  • filecheckmarx-util-1.0.4.tgz
  • filetpcp.tar.gz
  • filesysmon.py
  • observabledocs-tpcp GitHub repository used as fallback exfiltration path.
  • observableOpenVSX extensions fetched checkmarx-util-1.0.4.tgz from checkmarx.zone/static.

References

  1. Update: Ongoing Checkmarx Supply Chain Security Incidentcheckmarx.com
  2. Update: Ongoing Checkmarx Supply Chain Security Incidentcheckmarx.com
  3. KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attackwiz.io
  4. Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tagsstepsecurity.io
  5. TeamPCP Deploys SANDCLOCK Cloud Stealer in Checkmarx Breachsysdig.com
  6. TeamPCP Supply Chain Attack Targets Checkmarx and Trivyarcticwolf.com

Source record: proprietary/checkmarx-ast/meta.yaml