Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Checkmarx Supply Chain Attack Leads to Data Breach

Checkmarx Supply Chain Attack Leads to Data Breach

Posted on April 29, 2026 By CWS

Checkmarx recently confirmed that a supply chain attack on its KICS open source project resulted in unauthorized data access. The breach occurred last month and was linked to the Trivy supply chain attack, which allowed hackers to alter GitHub Action version tags covertly.

Impact of the Supply Chain Attack

This attack has been attributed to TeamPCP, a notorious hacking group involved in a broader campaign targeting multiple open source software ecosystems. The objective was to steal credentials and sensitive information. Around the time Checkmarx was compromised, messages from TeamPCP and the Lapsus$ extortion group indicated possible collaboration for financial gain.

Subsequently, Lapsus$ listed Checkmarx on its Tor-based leak site, claiming to have acquired source code, employee databases, API keys, and database credentials. Checkmarx confirmed that the breach stemmed from compromised GitHub repositories accessed via credentials obtained in the initial attack on March 23, 2026.

Response to the Breach

The hackers exploited Checkmarx’s GitHub environment by using credentials compromised through the Trivy hack. They targeted two OpenVSX plugins and GitHub Actions workflows. In response, Checkmarx removed the malicious packages, rotated compromised credentials, and blocked access to the hacker’s infrastructure.

Despite these efforts, the attackers managed to re-enter the environment and on April 22, they deployed additional malicious code, affecting a DockerHub KICS image, a GitHub action, a VS Code extension, and a Developer Assist extension. These actions also led to a compromise of the Bitwarden CLI NPM package, a widely-used open source password manager.

Ongoing Investigation and Mitigation Efforts

Checkmarx revealed that data exfiltration occurred on March 30, 2026. As part of its ongoing investigation, the company has engaged law enforcement, partnered with Mandiant for further analysis, reset a broad range of credentials, enhanced security measures, secured GitHub repositories, and initiated a code audit.

Checkmarx has stated that they are nearing the conclusion of their investigation, confirming that unauthorized access has been contained. The company plans to release more information as it becomes available.

Related incidents in the cybersecurity landscape include data breaches at Vimeo, luxury cosmetics giant Rituals, and healthcare organizations in Illinois and Texas.

Security Week News Tags:API keys, Checkmarx, Cybersecurity, data breach, GitHub, Hacking, LAPSUS, Open Source, supply chain attack, TeamPCP

Post navigation

Previous Post: Update Your cPanel Server to Fix Critical Vulnerability
Next Post: LofyStealer Targets Minecraft Players with Advanced Tactics

Related Posts

DoE Unveils Strategic 5-Year Energy Security Plan DoE Unveils Strategic 5-Year Energy Security Plan Security Week News
North Korean Hackers Take Over Victims’ Systems Using Zoom Meeting North Korean Hackers Take Over Victims’ Systems Using Zoom Meeting Security Week News
North Korean APT37’s New Tools Target Air-Gapped Systems North Korean APT37’s New Tools Target Air-Gapped Systems Security Week News
Rise in Supply Chain Attacks Highlights SBOM Challenges Rise in Supply Chain Attacks Highlights SBOM Challenges Security Week News
Marks & Spencer Says Data Stolen in Ransomware Attack Marks & Spencer Says Data Stolen in Ransomware Attack Security Week News
Google Enhances Pixel Security with Rust DNS Parser Google Enhances Pixel Security with Rust DNS Parser Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis
  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide
  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis
  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide
  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark