logo

Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

ID: 05f620a0-b960-5b1c-b6fd-5226d1949afa

STIX ID: report--05f620a0-b960-5b1c-b6fd-5226d1949afa

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: [email protected] (The Hacker News)

...
...

Checkmarx disclosed that an ongoing investigation into a March 23, 2026 supply-chain attack found data from its GitHub repository posted on the dark web; the company says the repo is separate from customer production environments and is investigating the scope but has locked access. The leaked material is reported to include source code, an employee database, API keys, and MongoDB/MySQL credentials, and the incident involved tampered GitHub Actions workflows and VS Code/Open VSX plugins that pushed a credential-stealing malware; TeamPCP claimed responsibility and LAPSUS$ listed Checkmarx as a victim, with a cascading impact briefly affecting other packages such as the Bitwarden CLI npm package.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.