Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Checkmarx Data Breach: GitHub Data Exposed on Dark Web

Checkmarx Data Breach: GitHub Data Exposed on Dark Web

Posted on April 27, 2026 By CWS

Checkmarx Data Breach Unveiled

Checkmarx, a prominent player in cybersecurity, has confirmed a significant breach involving its GitHub repository data, now posted on the dark web. This revelation stems from an ongoing investigation into a security incident initially detected on March 23, 2026. The breach is believed to be connected to a supply chain attack that facilitated unauthorized access to the company’s GitHub repository.

Details of the Data Breach

The Israeli security firm clarified that the compromised GitHub repository operates independently of its customer production systems, highlighting that no customer data is stored within. Checkmarx is actively conducting a forensic examination to assess the scope and nature of the leaked data. As a precautionary measure, the company has restricted access to the affected repository.

In response to the incident, Checkmarx has assured stakeholders that should customer information be implicated, they will promptly inform all relevant parties. The investigation is part of the company’s comprehensive incident response strategy.

Implications of the Dark Web Posting

The breach gained wider attention following a post by Dark Web Informer, indicating that the LAPSUS$ cybercriminal group has listed Checkmarx among its victims on a data leak site. The exposed data allegedly includes sensitive elements such as source code, employee databases, API keys, and credentials for MongoDB/MySQL.

The breach is linked to the Trivy supply chain attack, which compromised Checkmarx’s GitHub Actions workflows and plugins in the Open VSX marketplace. The attackers, identified as TeamPCP, used the breach to distribute a credential-stealing malware targeting developer secrets.

Security Consequences and Future Actions

Recently, the same group is suspected to have targeted Checkmarx’s KICS Docker image, along with two VS Code extensions, further propagating the malware. This chain of events led to a temporary compromise of the Bitwarden CLI npm package.

The ongoing investigation by Checkmarx aims to fully comprehend the breach’s impact and prevent future occurrences. As the situation develops, the company remains committed to transparency and safeguarding its systems against such threats.

In conclusion, Checkmarx’s swift response and ongoing efforts to secure its systems underscore the importance of robust cybersecurity measures in an increasingly digital world.

The Hacker News Tags:Checkmarx, credential stealer, Cybersecurity, dark web, data breach, GitHub, LAPSUS, security incident, supply chain attack, TeamPCP

Post navigation

Previous Post: Security Alert: macOS textutil and KeePassXC Risks
Next Post: Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access

Related Posts

IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More The Hacker News
Critical React Native CLI Flaw Exposed Millions of Developers to Remote Attacks Critical React Native CLI Flaw Exposed Millions of Developers to Remote Attacks The Hacker News
iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and More iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and More The Hacker News
295 Malicious IPs Launch Coordinated Brute-Force Attacks on Apache Tomcat Manager 295 Malicious IPs Launch Coordinated Brute-Force Attacks on Apache Tomcat Manager The Hacker News
Why Data Security and Privacy Need to Start in Code Why Data Security and Privacy Need to Start in Code The Hacker News
Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Patches Critical Gemini CLI Vulnerability
  • ClickUp’s API Key Leak Exposes Fortune 500 Emails
  • New Fast16 Malware Uncovered: Cybersecurity Concerns Rise
  • Notepad++ Flaw Poses Security Risk for Developers
  • Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Patches Critical Gemini CLI Vulnerability
  • ClickUp’s API Key Leak Exposes Fortune 500 Emails
  • New Fast16 Malware Uncovered: Cybersecurity Concerns Rise
  • Notepad++ Flaw Poses Security Risk for Developers
  • Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark