Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Checkmarx Data Breach: GitHub Data Exposed on Dark Web

Checkmarx Data Breach: GitHub Data Exposed on Dark Web

Posted on April 27, 2026 By CWS

Checkmarx Data Breach Unveiled

Checkmarx, a prominent player in cybersecurity, has confirmed a significant breach involving its GitHub repository data, now posted on the dark web. This revelation stems from an ongoing investigation into a security incident initially detected on March 23, 2026. The breach is believed to be connected to a supply chain attack that facilitated unauthorized access to the company’s GitHub repository.

Details of the Data Breach

The Israeli security firm clarified that the compromised GitHub repository operates independently of its customer production systems, highlighting that no customer data is stored within. Checkmarx is actively conducting a forensic examination to assess the scope and nature of the leaked data. As a precautionary measure, the company has restricted access to the affected repository.

In response to the incident, Checkmarx has assured stakeholders that should customer information be implicated, they will promptly inform all relevant parties. The investigation is part of the company’s comprehensive incident response strategy.

Implications of the Dark Web Posting

The breach gained wider attention following a post by Dark Web Informer, indicating that the LAPSUS$ cybercriminal group has listed Checkmarx among its victims on a data leak site. The exposed data allegedly includes sensitive elements such as source code, employee databases, API keys, and credentials for MongoDB/MySQL.

The breach is linked to the Trivy supply chain attack, which compromised Checkmarx’s GitHub Actions workflows and plugins in the Open VSX marketplace. The attackers, identified as TeamPCP, used the breach to distribute a credential-stealing malware targeting developer secrets.

Security Consequences and Future Actions

Recently, the same group is suspected to have targeted Checkmarx’s KICS Docker image, along with two VS Code extensions, further propagating the malware. This chain of events led to a temporary compromise of the Bitwarden CLI npm package.

The ongoing investigation by Checkmarx aims to fully comprehend the breach’s impact and prevent future occurrences. As the situation develops, the company remains committed to transparency and safeguarding its systems against such threats.

In conclusion, Checkmarx’s swift response and ongoing efforts to secure its systems underscore the importance of robust cybersecurity measures in an increasingly digital world.

The Hacker News Tags:Checkmarx, credential stealer, Cybersecurity, dark web, data breach, GitHub, LAPSUS, security incident, supply chain attack, TeamPCP

Post navigation

Previous Post: Security Alert: macOS textutil and KeePassXC Risks
Next Post: Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access

Related Posts

Cybersecurity Updates: Qualcomm Flaw and iOS Exploit Chains Cybersecurity Updates: Qualcomm Flaw and iOS Exploit Chains The Hacker News
Safeguarding AI Agents Through Effective Delegation Safeguarding AI Agents Through Effective Delegation The Hacker News
Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems The Hacker News
Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome The Hacker News
New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts The Hacker News
CPUID Breach: STX RAT Spread via Compromised Downloads CPUID Breach: STX RAT Spread via Compromised Downloads The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices
  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices
  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark