Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Checkmarx Supply Chain Attack Leads to Data Breach

Checkmarx Supply Chain Attack Leads to Data Breach

Posted on April 29, 2026 By CWS

Checkmarx recently confirmed that a supply chain attack on its KICS open source project resulted in unauthorized data access. The breach occurred last month and was linked to the Trivy supply chain attack, which allowed hackers to alter GitHub Action version tags covertly.

Impact of the Supply Chain Attack

This attack has been attributed to TeamPCP, a notorious hacking group involved in a broader campaign targeting multiple open source software ecosystems. The objective was to steal credentials and sensitive information. Around the time Checkmarx was compromised, messages from TeamPCP and the Lapsus$ extortion group indicated possible collaboration for financial gain.

Subsequently, Lapsus$ listed Checkmarx on its Tor-based leak site, claiming to have acquired source code, employee databases, API keys, and database credentials. Checkmarx confirmed that the breach stemmed from compromised GitHub repositories accessed via credentials obtained in the initial attack on March 23, 2026.

Response to the Breach

The hackers exploited Checkmarx’s GitHub environment by using credentials compromised through the Trivy hack. They targeted two OpenVSX plugins and GitHub Actions workflows. In response, Checkmarx removed the malicious packages, rotated compromised credentials, and blocked access to the hacker’s infrastructure.

Despite these efforts, the attackers managed to re-enter the environment and on April 22, they deployed additional malicious code, affecting a DockerHub KICS image, a GitHub action, a VS Code extension, and a Developer Assist extension. These actions also led to a compromise of the Bitwarden CLI NPM package, a widely-used open source password manager.

Ongoing Investigation and Mitigation Efforts

Checkmarx revealed that data exfiltration occurred on March 30, 2026. As part of its ongoing investigation, the company has engaged law enforcement, partnered with Mandiant for further analysis, reset a broad range of credentials, enhanced security measures, secured GitHub repositories, and initiated a code audit.

Checkmarx has stated that they are nearing the conclusion of their investigation, confirming that unauthorized access has been contained. The company plans to release more information as it becomes available.

Related incidents in the cybersecurity landscape include data breaches at Vimeo, luxury cosmetics giant Rituals, and healthcare organizations in Illinois and Texas.

Security Week News Tags:API keys, Checkmarx, Cybersecurity, data breach, GitHub, Hacking, LAPSUS, Open Source, supply chain attack, TeamPCP

Post navigation

Previous Post: Update Your cPanel Server to Fix Critical Vulnerability
Next Post: LofyStealer Targets Minecraft Players with Advanced Tactics

Related Posts

Senate Approves Joshua Rudd for NSA and Cyber Command Senate Approves Joshua Rudd for NSA and Cyber Command Security Week News
Ox Security Launches AI Agent That Auto-Generates Code to Fix Vulnerabilities Ox Security Launches AI Agent That Auto-Generates Code to Fix Vulnerabilities Security Week News
US Announces Botnet Takedown, Charges Against Russian Administrators US Announces Botnet Takedown, Charges Against Russian Administrators Security Week News
European Commission Data Breach from Trivy Attack Unveiled European Commission Data Breach from Trivy Attack Unveiled Security Week News
Organizations Warned of Vulnerability Exploited Against Discontinued TP-Link Routers Organizations Warned of Vulnerability Exploited Against Discontinued TP-Link Routers Security Week News
New Reports Reinforce Cyberattack’s Role in Maduro Capture Blackout New Reports Reinforce Cyberattack’s Role in Maduro Capture Blackout Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Exposed VNC Servers Threaten Industrial Control Systems
  • Choosing the Right Exposure Management Platform
  • LofyStealer Targets Minecraft Players with Advanced Tactics
  • Checkmarx Supply Chain Attack Leads to Data Breach
  • Update Your cPanel Server to Fix Critical Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Exposed VNC Servers Threaten Industrial Control Systems
  • Choosing the Right Exposure Management Platform
  • LofyStealer Targets Minecraft Players with Advanced Tactics
  • Checkmarx Supply Chain Attack Leads to Data Breach
  • Update Your cPanel Server to Fix Critical Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark