[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faHpqeDB3Bcw9vx13gxBr1ReB46bKMP3_oaTvrNYrWAU":3},{"article":4,"iocs":38,"watch_terms":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"0830c647-09b6-4292-bb12-dacb41370b45","Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit","checkmarx-kics-code-scanner-targeted-in-widening-supply-chain-hit","TeamPCP is the likely cyber threat actor behind attacks on Trivy, Checkmarx's KICS and VS Code plug-ins, and the LiteLLM AI library — and all signs point to more attacks to come.","TeamPCP, an identified cyber threat actor, has launched coordinated attacks against multiple widely-used open-source and commercial security tools, including Checkmarx's KICS code scanner, Trivy vulnerability scanner, VS Code plugins, and the LiteLLM AI library. The campaign suggests a deliberate targeting of developer infrastructure and tools used across the software development lifecycle. Security researchers assess that additional attacks are likely as the threat actor continues probing the supply chain ecosystem.","TeamPCP threat actor targets Checkmarx KICS, Trivy, VS Code plugins, and LiteLLM in widening supply chain campaign.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fapplication-security\u002Fcheckmarx-kics-code-scanner-widening-supply-chain","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fbltc695e46616cc03ae\u002F69c2f4e89279f2162fe82972\u002Fsschain_ImageFlow_shutterstock.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-03-24T21:28:16+00:00","2026-03-24T23:00:10.527552+00:00",8,[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":18,"icon":11,"name":20,"slug":21},"Supply Chain","supply-chain",[23,28,33],{"category":24},{"id":25,"icon":11,"name":26,"slug":27},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[39,42,45,48],{"type":27,"value":40,"context":41},"TeamPCP","Threat actor conducting supply chain attacks against multiple dev tools and libraries",{"type":27,"value":43,"context":44},"KICS","Checkmarx code scanner targeted in supply chain attack",{"type":27,"value":46,"context":47},"Trivy","Vulnerability scanner targeted in supply chain attack",{"type":27,"value":49,"context":50},"LiteLLM","AI library targeted in supply chain attack campaign",[]]