Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
    Cybersecurity

    Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

    adminBy adminApril 27, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 27, 2026

    Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web.

    “Based on current evidence, we believe this data originated from Checkmarx’s GitHub repository, and that access to that repository was facilitated through the initial supply chain attack of March 23, 2026,” the Israeli security company said.

    It also emphasized that the GitHub repository is maintained separately from its customer production environment, adding that no customer data is stored in the repository. Checkmarx said its forensic probe into the incident is ongoing and that it’s actively working to verify the nature and scope of the posted data.

    Furthermore, the company said it has locked down access to the affected GitHub repository as part of its incident response efforts.

    “If we determine that customer information was involved in this incident, we will notify customers and all relevant parties immediately,” it said.

    The development comes after the Dark Web Informer shared in an X post that the LAPSUS$ cybercrime group claimed three victims on its data leak site, one of which includes Checkmarx. The data, per the listing, contains source code, employee database, API keys, and MongoDB/MySQL credentials.

    Checkmarx suffered a breach late last month following the Trivy supply chain attack, as a result of which two of its GitHub Actions workflows and two plugins distributed via the Open VSX marketplace were tampered with to push a credential stealer capable of harvesting a wide range of developer secrets. The threat actor known as TeamPCP claimed responsibility for the attack.

    Last week, the financially motivated group is suspected to have compromised Checkmarx’s KICS Docker image, along with the two VS Code extensions and a GitHub Actions workflow with a similar credential-stealing malware. This, in turn, had a cascading impact, leading to a brief compromise of the Bitwarden CLI npm package.

    Attack Checkmarx confirms dark data GitHub March Posted Repository Web
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow AI is reshaping traffic channels
    Next Article Adthena launches Google Ads-to-ChatGPT conversion tool
    admin
    • Website

    Related Posts

    Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation

    April 27, 2026

    Major critical infrastructure supplier reports cyberattack

    April 27, 2026

    Medtronic confirms breach after hackers claim 9 million records theft

    April 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    The Internet Still Works: SmugMug Powers Online Photography

    April 27, 2026

    How to Lower Your Cost Per Click in Google Ads & Meta Ads

    April 27, 2026

    Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation

    April 27, 2026

    Adthena launches Google Ads-to-ChatGPT conversion tool

    April 27, 2026
    Categories
    • Blogging (69)
    • Cybersecurity (1,537)
    • Privacy & Online Earning (185)
    • SEO & Digital Marketing (938)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (246)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    The Internet Still Works: SmugMug Powers Online Photography

    April 27, 2026

    How to Lower Your Cost Per Click in Google Ads & Meta Ads

    April 27, 2026

    Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation

    April 27, 2026
    Most Popular
    • The Internet Still Works: SmugMug Powers Online Photography
    • How to Lower Your Cost Per Click in Google Ads & Meta Ads
    • Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation
    • Adthena launches Google Ads-to-ChatGPT conversion tool
    • Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
    • How AI is reshaping traffic channels
    • Major critical infrastructure supplier reports cyberattack
    • Medtronic confirms breach after hackers claim 9 million records theft
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.