INTEL_REPORT
Trend Micro Research · published 5/13/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft Our research examines the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused trusted CI/CD and release workflows to steal credentials at scale. Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft | Trend Micro (US) search cl…
https://www.trendmicro.com/en_us/research/26/e/analyzing-teampcp-supply-chain-attacks.html
sha256:cf06e186a53e5536d1bc2448c54759eb84852cd6aff039b351d564c47ad9a6ee
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| github.event.comment.body |
| Open → |
| domain | ghcr.io | Open → |
| domain | elementary.pth | Open → |
| domain | credentials.toml | Open → |
| domain | trin.tar.gz | Open → |
| domain | litter.catbox.moe | Open → |
| domain | bun.exe | Open → |
| domain | tpcp.tar.gz | Open → |
| domain | iqesmbhukgd2c7hq.sh | Open → |
| domain | subprocess.run | Open → |
| domain | tempfile.temporarydirectory | Open → |
| domain | terraform.tfstate | Open → |
| domain | gitlab-ci.yml | Open → |
| domain | env.production | Open → |
| domain | github.event.issue.title | Open → |