2026 Checkmarx — LAPSUS$ leaks ~96 GB from GitHub; Trivy supply-chain pivot (Apr)
Data compromised
Source code, signing or build artifacts, and developer secrets as typical for compromised repos—customer DBs explicitly excluded in early company statements
Technical writeup
In late April 2026, Checkmarx confirmed that data the LAPSUS$ extortion group published matched material taken from its private GitHub environment, stemming from access beginning March 23, 2026. BleepingComputer and Checkmarx incident blogs described a chain where credentials exposed via the separate Trivy open-source scanner supply-chain compromise (TeamPCP–attributed) enabled interaction with Checkmarx’s GitHub org, subsequent publication of malicious artifacts (including KICS-related Docker images and editor extensions), and eventual exfiltration characterized as a ~96 GB pack surfaced on both dark-web and clearnet extortion infrastructure. The vendor stated GitHub does not house end-customer databases but promised notification if forensics identified consumer PII inside repositories; access was blocked pending investigation.
Root cause
Credential reuse / supply-chain pivot from Trivy incident into GitHub publishing and persistence (per Checkmarx narrative)