<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Checkmarx Confirms Data Theft Following Multi-Stage Supply Chain Attack

Checkmarx confirms data theft in a supply chain attack via GitHub Actions, involving TeamPCP and Lapsus$, now fully contained.
Content Team

Cybersecurity firm Checkmarx has confirmed that hackers stole data during a supply chain attack that began March 23, 2026. The breach, traced to the Trivy supply chain hack, allowed the TeamPCP group — potentially partnered with the Lapsus$ extortion gang — to hijack GitHub Actions and poison multiple open source packages. A second attack wave on April 22 compromised a DockerHub image and even the Bitwarden CLI NPM package. Lapsus$ later dumped a 96GB archive online, claiming it contained source code, employee data, and credentials. Checkmarx has since hired Mandiant, notified law enforcement, and says the breach is now fully contained.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo