← Checkmarx

2026 Checkmarx — LAPSUS$ leaks ~96 GB from GitHub; Trivy supply-chain pivot (Apr)

2026 Unknown records affected Share on X

Data compromised

Source code, signing or build artifacts, and developer secrets as typical for compromised repos—customer DBs explicitly excluded in early company statements

Technical writeup

In late April 2026, Checkmarx confirmed that data the LAPSUS$ extortion group published matched material taken from its private GitHub environment, stemming from access beginning March 23, 2026. BleepingComputer and Checkmarx incident blogs described a chain where credentials exposed via the separate Trivy open-source scanner supply-chain compromise (TeamPCP–attributed) enabled interaction with Checkmarx’s GitHub org, subsequent publication of malicious artifacts (including KICS-related Docker images and editor extensions), and eventual exfiltration characterized as a ~96 GB pack surfaced on both dark-web and clearnet extortion infrastructure. The vendor stated GitHub does not house end-customer databases but promised notification if forensics identified consumer PII inside repositories; access was blocked pending investigation.

Root cause

Credential reuse / supply-chain pivot from Trivy incident into GitHub publishing and persistence (per Checkmarx narrative)

References