logo

Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data

ID: 02587a48-e3fa-5574-a779-96dc7f5256ca

STIX ID: report--02587a48-e3fa-5574-a779-96dc7f5256ca

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Bill Toulas

...
...

Checkmarx confirmed that the LAPSUS$ group used credentials obtained from a March 23 Trivy supply‑chain incident to access the company's GitHub repository, publish malicious code, and later release a 96GB data package; on April 22 attackers also published malicious Docker images and VSCode/Open VSX extensions for Checkmarx’s KICS scanner that reportedly stole credentials, keys, tokens, and configuration files while an investigation and forensic analysis are ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.