Checkmarx disclosed on April 22, 2026, that its GitHub account had been compromised and used to push malware to its users, the second such incident affecting the security firm in 40 days. The company said it took action to remove the attackers from the account and contain the distribution of malicious code.
The April 22, 2026, incident followed a March 23, 2026, breach in which Checkmarx's GitHub account was compromised and began pushing malware to users. Checkmarx contained and remediated that earlier breach and replaced the malware with the legitimate applications.
Checkmarx said the ransomware group tracked as Lapsu$ dumped private data onto the dark web the previous week. The dumped material carried a date stamp of March 30. The company did not specify which kinds of data were leaked.
"Current evidence indicates that this data originated from Checkmarx's GitHub repositories, and that access to those repositories was facilitated through the initial supply chain attack of March 23, 2023," Checkmarx said. The quote refers to the year 2023 as stated in Checkmarx's own disclosure.
The breaches form part of a broader pattern targeting security tooling. On March 19, 2026, attackers breached the GitHub account of Trivy, a vulnerability scanner, and pushed malware to Trivy users, including Checkmarx. The malware scanned infected machines for repository tokens, SSH keys, and other credentials. The official Checkmarx/kics Docker Hub repository published malicious packages around the same time, according to security firm Socket.
Bitwarden was also affected by the supply-chain attack on Trivy, according to Socket. The Bitwarden breach used a payload with the same command-and-control endpoint and core infrastructure as the malware in the Checkmarx incident. "A malicious package was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026," Bitwarden said.
The Trivy attack was carried out by a group calling itself TeamPCP, an access-broker operation that obtains credentials from victims and sells them to other hackers and targets tools that already have privileged access. TeamPCP sold access credentials to Lapsu$, a ransomware group composed mostly of teenagers.
"You will see this same thread throughout these compromises," said Feross Aboukhadijeh, CEO of Socket. "Attackers are treating security tools as both a target and a delivery mechanism. They are attacking the products that are supposed to protect the supply chain, then using those same products to steal credentials and move to the next victim."
forum Comments (0)
No comments yet. Be the first to comment.