Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis of the poisoned image indicates that the bundled KICS binary was modified to include data collection and exfiltration capabilities not present in the legitimate version... the malware could generate an uncensored scan report, encrypt it, and send it to an external endpoint.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actors behind TeamPCP’s supply chain campaign are now using credentials stolen during earlier compromises to access Amazon Web Services (AWS) accounts... They rely on valid keys and trusted automation paths, allowing them to bypass authentication controls and blend into normal developer and pipeline activity.
The attackers validated cloud keys taken from the Trivy, LiteLLM, and Checkmarx KICS compromises and used them to access cloud services, enumerate infrastructure, run commands inside containers, and exfiltrate sensitive data.
The evidence suggests this is not an isolated Docker Hub incident, but part of a broader supply chain compromise affecting multiple Checkmarx distribution channels.
Docker alerted Socket to malicious images pushed to the official checkmarx/kics Docker Hub repository... attackers appear to have overwritten existing tags... Analysis of the poisoned image indicates that the bundled KICS binary was modified...
the threat actors behind TeamPCP’s supply chain campaign are now using credentials stolen during earlier compromises to access Amazon Web Services (AWS) accounts... They rely on valid keys and trusted automation paths, allowing them to bypass authentication controls and blend into normal developer and pipeline activity.
the threat actors behind TeamPCP’s supply chain campaign are now using credentials stolen during earlier compromises to access Amazon Web Services (AWS) accounts... They rely on valid keys and trusted automation paths, allowing them to bypass authentication controls and blend into normal developer and pipeline activity.
the threat actors behind TeamPCP’s supply chain campaign are now using credentials stolen during earlier compromises to access Amazon Web Services (AWS) accounts... They rely on valid keys and trusted automation paths, allowing them to bypass authentication controls and blend into normal developer and pipeline activity.
It iterated through th e /proc/ directory to isolate the PIDs for the .NET runtime powering the Runner.Worker process. Because the script inherited the runner’s user privileges, it read the /proc/<pid>/mem file descriptor , mapped the memory boundaries via /proc/<pid>/maps, and ran string-matching algorithms across the heap memory segments.
The attackers validated cloud keys taken from the Trivy, LiteLLM, and Checkmarx KICS compromises and used them to access cloud services... Rotating all secrets exposed in any environment where compromised packages were installed, including cloud access keys, Secure Shell keys, and GitHub tokens.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.