Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data
ID: 02587a48-e3fa-5574-a779-96dc7f5256ca
STIX ID: report--02587a48-e3fa-5574-a779-96dc7f5256ca
Feed Name: Bleeping Computer
Threat Score
Checkmarx confirmed that the LAPSUS$ group used credentials obtained from a March 23 Trivy supply‑chain incident to access the company's GitHub repository, publish malicious code, and later release a 96GB data package; on April 22 attackers also published malicious Docker images and VSCode/Open VSX extensions for Checkmarx’s KICS scanner that reportedly stole credentials, keys, tokens, and configuration files while an investigation and forensic analysis are ongoing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
