logo

Checkmarx Falls Victim to Credential Harvesting Attack

ID: 4c1f589d-1a5d-588f-a857-1b7f0b22bd21

STIX ID: report--4c1f589d-1a5d-588f-a857-1b7f0b22bd21

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Ddos

...
...

Checkmarx disclosed a Trivy supply-chain attack that enabled attackers to harvest credentials and access its GitHub repositories, resulting in malicious code commits, data exfiltration over multiple weeks, a second wave of malicious artifacts, and the subsequent publication of stolen data by the LAPSUS$ group; Checkmarx says customer production environments were not stored in the affected GitHub repositories and remediation is ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.