Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

On April 22, 2026, threat actor TeamPCP compromised the Checkmarx KICS open-source infrastructure-as-code scanning toolchain across three simultaneous channels: Docker Hub, VS Code Marketplace, and Open VSX, during a 90-minute exposure window. Malicious artifacts were designed to steal cloud credentials (AWS, GCP, Azure), GitHub tokens, SSH keys, and CI/CD secrets from developer pipelines that pulled affected packages. Any organization that consumed KICS artifacts during that window faces confirmed credential compromise risk across cloud and source control environments, with direct exposure to unauthorized cloud access, data exfiltration, and pipeline takeover.

Author

Tech Jacks Solutions