Cyber Incident Victim: Checkmarx
Timeline
Summary
Checkmarx confirmed that a supply chain attack on its KICS open source project led to credential theft, allowing attackers to hijack GitHub Action tags and poison OpenVSX plugins, workflows, a DockerHub image, VS Code and Developer Assist extensions, and the Bitwarden CLI NPM package. The intrusion enabled exfiltration of source code, employee data, API keys, and database credentials, which were later posted on a leak site. After detecting the breach, the firm removed malicious packages, revoked credentials, blocked attacker infrastructure, notified law enforcement, engaged Mandiant, reset credentials broadly, tightened controls, locked down repository access, and initiated a code audit to contain the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 2 actors | Available to members | Available to members |
Description
Checkmarx confirmed on April 22, 2026 that a supply chain attack targeting its KICS open source project resulted in data theft. The compromise stemmed from the Trivy supply chain attack on March 23, 2026, which allowed attackers to hijack dozens of GitHub Action version tags to reference malware without visible changes. The intrusion was attributed to the TeamPCP hacking group and was part of a broader campaign targeting multiple open source ecosystems for credential and sensitive information theft. Around the same time, messages from TeamPCP and the Lapsus$ extortion group indicated a possible partnership for monetization purposes. Hackers used credentials compromised via the Trivy hack to access Checkmarx’s GitHub environment, poisoning two OpenVSX plugins and two GitHub Actions workflows.

After removing the malicious packages and rotating credentials, Checkmarx observed that the attackers retained or regained access and on April 22, 2026 published a fresh round of malicious code by poisoning a DockerHub KICS image, a GitHub action, a VS Code extension, and a Developer Assist extension. This second wave also led to the compromise of the Bitwarden command‑line interface NPM package, a widely used open source password management tool. One month after the initial compromise, Lapsus$ added Checkmarx to its Tor‑based leak site, claiming the theft of source code, employee databases, API keys, and MongoDB and MySQL credentials. Checkmarx stated that the exfiltrated data originated from its GitHub repositories and that the data theft occurred on March 30, 2026. As part of the attack’s final phase, the attackers published a 96GB archive containing the alleged stolen data.
In response, Checkmarx notified law enforcement, retained Mandiant to assist with the investigation, and performed a broader credential reset. The company strengthened security controls, locked down access to its GitHub repositories, and launched a code audit. Checkmarx removed the malicious packages, revoked and rotated relevant credentials, and blocked outbound access to the attacker’s infrastructure. The company said it is now in the final stages of its investigation and confirming that the unauthorized access has been fully contained, and will share further details when able.
