Live
eineurope/
Home/Global/Topic · Checkmarx Breach Expands Supply Chain Attack
Global19h ago

Checkmarx Breach Expands Supply Chain Attack

Checkmarx confirms GitHub compromise after Lapsus$ leaks source code and credentials; attack chain hits Bitwarden CLI affecting 10M+ users.

Sources
1 verified
Location
Updated
Tuesday, 28 April 2026 at 05:01 UTC
No media · text-only dispatch
Synthesis · 1 sources
Checkmarx confirmed a GitHub repository compromise after the Lapsus$ hacking group published alleged source code, API keys, and database credentials. The breach originated from a March 23 attack on Checkmarx's KICS tool, which itself stemmed from TeamPCP's earlier compromise of Aqua Security's Trivy scanner. The malware-laced KICS binary exfiltrated infrastructure-as-code scan results containing credentials. The attack chain now extends to Bitwarden CLI, affecting over 10 million users and 50,000 businesses.
e/eineurope · topic · T-09678