Checkmarx Security Breach: LAPSUS$ Hackers Leak Stolen GitHub Data (2026)

Checkmarx, a prominent application security company, has recently fallen victim to a sophisticated cyber-attack orchestrated by the LAPSUS$ threat group. This incident has exposed a significant breach within the company's GitHub repositories, highlighting the vulnerabilities that exist within the supply chain. The attack, which occurred on March 23, 2026, involved the publication of malicious code and the theft of sensitive data, including credentials, keys, tokens, and configuration files. The repercussions of this breach extend beyond Checkmarx, as the LAPSUS$ group has made the stolen data accessible through both dark web and clearnet portals, raising concerns about the potential impact on downstream users and the broader cybersecurity landscape.

What makes this incident particularly alarming is the method employed by the attackers. The Trivy supply-chain attack, attributed to the hacker group TeamPCP, provided the initial access vector. This attack exploited a vulnerability in the Trivy vulnerability scanner, which was then used to obtain stolen credentials from downstream users. These credentials were then utilized to gain unauthorized access to Checkmarx's GitHub repositories, where the attackers published malicious code and potentially sensitive information.

The aftermath of this breach has been far-reaching. On April 22, the attackers renewed their access to the compromised repositories and published malicious Docker images and VSCode and Open VSX extensions for Checkmarx's KICS security scanner. These actions not only compromised the security of the KICS tool but also raised concerns about the security of the company's products and services. The LAPSUS$ group's extortion portal further emphasized the severity of the breach, as it contained data that originated from Checkmarx's GitHub repository.

One of the most concerning aspects of this incident is the potential exposure of customer information. While Checkmarx has assured that customer data is not stored in its GitHub repository, the forensic investigation is ongoing to determine the exact type of data that has been exposed. If customer information is found, affected individuals will be promptly notified, and the company will take the necessary steps to mitigate any potential harm.

This breach serves as a stark reminder of the interconnected nature of the cybersecurity ecosystem. The supply chain attack, in particular, highlights the vulnerability of downstream users and the potential for cascading effects. As the investigation continues, it is crucial for organizations to prioritize supply chain security and implement robust measures to prevent similar incidents in the future. The cybersecurity community must remain vigilant and proactive in addressing these threats to ensure the protection of sensitive data and the integrity of digital systems.

Checkmarx Security Breach: LAPSUS$ Hackers Leak Stolen GitHub Data (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Madonna Wisozk

Last Updated:

Views: 5846

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Madonna Wisozk

Birthday: 2001-02-23

Address: 656 Gerhold Summit, Sidneyberg, FL 78179-2512

Phone: +6742282696652

Job: Customer Banking Liaison

Hobby: Flower arranging, Yo-yoing, Tai chi, Rowing, Macrame, Urban exploration, Knife making

Introduction: My name is Madonna Wisozk, I am a attractive, healthy, thoughtful, faithful, open, vivacious, zany person who loves writing and wants to share my knowledge and understanding with you.