Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Checkmarx Data Breach: GitHub Data Exposed on Dark Web

Checkmarx Data Breach: GitHub Data Exposed on Dark Web

Posted on April 27, 2026 By CWS

Checkmarx Data Breach Unveiled

Checkmarx, a prominent player in cybersecurity, has confirmed a significant breach involving its GitHub repository data, now posted on the dark web. This revelation stems from an ongoing investigation into a security incident initially detected on March 23, 2026. The breach is believed to be connected to a supply chain attack that facilitated unauthorized access to the company’s GitHub repository.

Details of the Data Breach

The Israeli security firm clarified that the compromised GitHub repository operates independently of its customer production systems, highlighting that no customer data is stored within. Checkmarx is actively conducting a forensic examination to assess the scope and nature of the leaked data. As a precautionary measure, the company has restricted access to the affected repository.

In response to the incident, Checkmarx has assured stakeholders that should customer information be implicated, they will promptly inform all relevant parties. The investigation is part of the company’s comprehensive incident response strategy.

Implications of the Dark Web Posting

The breach gained wider attention following a post by Dark Web Informer, indicating that the LAPSUS$ cybercriminal group has listed Checkmarx among its victims on a data leak site. The exposed data allegedly includes sensitive elements such as source code, employee databases, API keys, and credentials for MongoDB/MySQL.

The breach is linked to the Trivy supply chain attack, which compromised Checkmarx’s GitHub Actions workflows and plugins in the Open VSX marketplace. The attackers, identified as TeamPCP, used the breach to distribute a credential-stealing malware targeting developer secrets.

Security Consequences and Future Actions

Recently, the same group is suspected to have targeted Checkmarx’s KICS Docker image, along with two VS Code extensions, further propagating the malware. This chain of events led to a temporary compromise of the Bitwarden CLI npm package.

The ongoing investigation by Checkmarx aims to fully comprehend the breach’s impact and prevent future occurrences. As the situation develops, the company remains committed to transparency and safeguarding its systems against such threats.

In conclusion, Checkmarx’s swift response and ongoing efforts to secure its systems underscore the importance of robust cybersecurity measures in an increasingly digital world.

The Hacker News Tags:Checkmarx, credential stealer, Cybersecurity, dark web, data breach, GitHub, LAPSUS, security incident, supply chain attack, TeamPCP

Post navigation

Previous Post: Security Alert: macOS textutil and KeePassXC Risks
Next Post: Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access

Related Posts

Why Non-Human Identity Management is the Next Cybersecurity Frontier Why Non-Human Identity Management is the Next Cybersecurity Frontier The Hacker News
Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep The Hacker News
[Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR [Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR The Hacker News
PowMix Botnet Targets Czech Workforce with Stealth Tactics PowMix Botnet Targets Czech Workforce with Stealth Tactics The Hacker News
Critical Chrome Vulnerability CVE-2026-11645 Actively Exploited Critical Chrome Vulnerability CVE-2026-11645 Actively Exploited The Hacker News
Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection
  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection
  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark