<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/checkmarx-kics-code-scanner-targeted-in-widening-supply-chain-hit-fpc0riglf" -->

---
title: Checkmarx KICS Code Scanner Targeted in Widening Supply...
description: A coordinated supply chain attack attributed to threat actor TeamPCP has compromised multiple developer tools: Checkmarx&#x27;s KICS GitHub Action and two VS Code...
canonical: https://daily.dev/posts/checkmarx-kics-code-scanner-targeted-in-widening-supply-chain-hit-fpc0riglf
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit | daily.dev
og:description: A coordinated supply chain attack attributed to threat actor TeamPCP has compromised multiple developer tools: Checkmarx&#x27;s KICS GitHub Action and two VS Code...
og:url: https://daily.dev/posts/checkmarx-kics-code-scanner-targeted-in-widening-supply-chain-hit-fpc0riglf
og:image: https://api.daily.dev/og/posts/FpC0RIGlf.png
og:image:alt: Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit

**[Dark Reading](https://daily.dev/sources/dr)** · 5 min read · 0 upvotes · 0 comments

## Summary

A coordinated supply chain attack attributed to threat actor TeamPCP has compromised multiple developer tools: Checkmarx's KICS GitHub Action and two VS Code plugins were poisoned on March 23, following a similar attack on Aqua Security's Trivy scanner. The campaign also spread to PyPI, infecting LiteLLM packages (versions 1.82.7 and 1.82.8) with infostealer malware capable of stealing SSH keys, cloud credentials, API tokens, Docker configs, and crypto wallet data. Wiz Research notes LiteLLM is present in 36% of cloud environments, suggesting a wide blast radius. Shared indicators of compromise link all incidents, and attackers have signaled more targets are coming, with Wiz reporting possible collaboration with the LAPSUS$ extortion group.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/application-security/checkmarx-kics-code-scanner-widening-supply-chain>

## Similar posts on daily.dev

- [Sophisticated Supply Chain Attack Targeting Trivy Expands to Checkmarx, LiteLLM](https://daily.dev/posts/sophisticated-supply-chain-attack-targeting-trivy-expands-to-checkmarx-litellm-setw9szuc) · DevOps.com · 0 upvotes · 0 comments
- [New Checkmarx supply-chain breach affects KICS analysis tool](https://daily.dev/posts/new-checkmarx-supply-chain-breach-affects-kics-analysis-tool-4pjc720zg) · BleepingComputer · 0 upvotes · 0 comments
- [Ongoing supply-chain attack targets security, dev tools](https://daily.dev/posts/ongoing-supply-chain-attack-targets-security-dev-tools-ovho9e01d) · The Register · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cicd](https://daily.dev/tags/cicd)

[View this post on daily.dev](https://daily.dev/posts/checkmarx-kics-code-scanner-targeted-in-widening-supply-chain-hit-fpc0riglf)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit","url":"https://daily.dev/posts/checkmarx-kics-code-scanner-targeted-in-widening-supply-chain-hit-fpc0riglf","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/checkmarx-kics-code-scanner-targeted-in-widening-supply-chain-hit-fpc0riglf"},"datePublished":"2026-03-24T21:49:26.794Z","dateModified":"2026-03-24T21:49:52.758Z","description":"A coordinated supply chain attack attributed to threat actor TeamPCP has compromised multiple developer tools: Checkmarx's KICS GitHub Action and two VS Code...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c0cad1bcdb448a338db09ad68d9137a1?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c0cad1bcdb448a338db09ad68d9137a1?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/checkmarx-kics-code-scanner-targeted-in-widening-supply-chain-hit-fpc0riglf","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cicd","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit"}]}
```

