Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
ID: 05f620a0-b960-5b1c-b6fd-5226d1949afa
STIX ID: report--05f620a0-b960-5b1c-b6fd-5226d1949afa
Feed Name: The Hacker News
Checkmarx disclosed that an ongoing investigation into a March 23, 2026 supply-chain attack found data from its GitHub repository posted on the dark web; the company says the repo is separate from customer production environments and is investigating the scope but has locked access. The leaked material is reported to include source code, an employee database, API keys, and MongoDB/MySQL credentials, and the incident involved tampered GitHub Actions workflows and VS Code/Open VSX plugins that pushed a credential-stealing malware; TeamPCP claimed responsibility and LAPSUS$ listed Checkmarx as a victim, with a cascading impact briefly affecting other packages such as the Bitwarden CLI npm package.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
