Checkmarx hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Checkmarx disclosed a breach tied to the March 23, 2026 Trivy supply-chain attack, and the compromise matters because attackers used it to tamper with GitHub Actions workflows and Open VSX marketplace plugins for credential theft. The malicious changes were designed to push a credential stealer capable of harvesting developer secrets. The company says the affected repository is maintained separately from customer production systems and has locked down access while the investigation continues.
Related Happenings
GitHub data exposed after GitHub breach
Data Leak
First: 20.05.2026 11:14
Last: 20.05.2026 11:14
Sources 1
About this happening:
GitHub confirmed **exfiltration** of **internal repositories**, making private code and related content potentially available to outsiders. Attackers on the **Breached cybercrime...
GitHub data exposed after GitHub breach
Data LeakAbout this happening: GitHub confirmed **exfiltration** of **internal repositories**, making private code and related content potentially available to outsiders. Attackers on the **Breached cybercrime...
Shai-Hulud public GitHub repository credential exposure
Data Leak
First: 18.05.2026 20:28
Last: 18.05.2026 20:28
Sources 1
About this happening:
**Shai-Hulud** stole **developer credentials** that were later exposed in **public GitHub repositories**, turning a theft phase into a public leak of access data. The exposed mate...
Shai-Hulud public GitHub repository credential exposure
Data LeakAbout this happening: **Shai-Hulud** stole **developer credentials** that were later exposed in **public GitHub repositories**, turning a theft phase into a public leak of access data. The exposed mate...
Grafana Labs Says GitHub hit by cyberattack
Incident
First: 17.05.2026 10:13
Last: 17.05.2026 10:13
Sources 1
About this happening:
A **Grafana Labs** incident was later tied to the **Mini Shai-Hulud** supply-chain campaign against **TanStack npm packages**. Grafana said an unauthorized party used a token to a...
Grafana Labs Says GitHub hit by cyberattack
IncidentAbout this happening: A **Grafana Labs** incident was later tied to the **Mini Shai-Hulud** supply-chain campaign against **TanStack npm packages**. Grafana said an unauthorized party used a token to a...
TeamPCP campaign expands across multiple victims
Campaign
First: 15.05.2026 13:54
Last: 15.05.2026 13:54
Sources 1
About this happening:
The **TeamPCP / Mini Shai-Hulud** supply-chain operation is actively compromising **hundreds of packages**, exposing **downstream developers** to **malware delivery** and **creden...
TeamPCP campaign expands across multiple victims
CampaignAbout this happening: The **TeamPCP / Mini Shai-Hulud** supply-chain operation is actively compromising **hundreds of packages**, exposing **downstream developers** to **malware delivery** and **creden...
Mistral AI hit by network compromise
Incident
First: 15.05.2026 01:50
Last: 15.05.2026 01:50
Sources 1
About this happening:
Mistral AI disclosed a **codebase management system compromise** tied to the **Mini Shai-Hulud** supply-chain attack, and the intrusion briefly contaminated some **SDK packages**....
Mistral AI hit by network compromise
IncidentAbout this happening: Mistral AI disclosed a **codebase management system compromise** tied to the **Mini Shai-Hulud** supply-chain attack, and the intrusion briefly contaminated some **SDK packages**....
Timeline
-
27.04.2026 17:19 2 articles · 1mo ago
Checkmarx supply chain attack tampers with GitHub Actions and Open VSX plugins
Exploitation ObservedA March 23, 2026 supply chain attack against Checkmarx led to tampering of two GitHub Actions workflows and two plugins distributed through the Open VSX marketplace to push a credential stealer capable of harvesting developer secrets; TeamPCP claimed responsibility for the attack.
Show sources
- Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack — thehackernews.com — 27.04.2026 17:19
- Official CheckMarx Jenkins package compromised with infostealer — www.bleepingcomputer.com — 12.05.2026 01:03
-
27.04.2026 17:19 1 articles · 1mo ago
Checkmarx confirms dark web publication of repository data
Initial DisclosureCheckmarx said its ongoing investigation found that a cybercriminal group published company data on the dark web, and current evidence indicates the data likely originated from Checkmarx's GitHub repository and was accessed through the March 23, 2026 supply chain attack; the company said the repository is maintained separately from customer production, no customer data is stored there, access has been locked down, and forensic verification of the posted data is ongoing.
Show sources
- Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack — thehackernews.com — 27.04.2026 17:19