INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Checkmarx Confirms GitHub Repository Data Posted on Dark Web After Attack

| 2026-04-27 14:19 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
Checkmarx confirmed that its GitHub repository data was posted on the dark web following a supply chain security incident in March 2026, specifically after the Trivy attack on March 23. The LAPSUS$ cybercrime group claimed three victims, including Checkmarx, and published sensitive information such as source code, employee database, API keys, and credentials. This breach occurred due to tampered GitHub Actions workflows and plugins distributed via the Open VSX marketplace, which pushed a credential stealer capable of harvesting developer secrets. The incident is suspected to have been carried out by LAPSUS$, with Checkmarx's KICS Docker image also compromised. As part of its response efforts, Checkmarx has locked down access to the affected GitHub repository and will notify customers if customer information was involved in the incident.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$
Target & Sectors
IL
technologytechnology
Incident Timeline
‎March 23, 2026
Threat actors, believed to be the financially motivated group LAPSUS$, compromised Checkmarx's KICS Docker image and associated tools on March 23.
threat_actor LAPSUS$
infrastructure Vs Code
Tactical Metrics
Metrics
infrastructure
‎Vs Code
Affected Product
Intelligence Sources