Checkmarx Confirms Dark Web Leak of GitHub Repo Data

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Checkmarx said a cybercriminal group posted data from its GitHub repository on the dark web, linking the leak to the March 23, 2026 supply‑chain attack.
- Checkmarx noted the repository is kept separate from its customer production environment and stores no customer data.
- Checkmarx locked down access to the affected GitHub repository as part of its incident‑response actions.
- Checkmarx pledged to notify customers immediately if the investigation finds that personal information was exposed.
- LAPSUS$ was identified by Dark Web Informer as one of three victims on its data‑leak site, with the posted files containing source code, employee database, API keys and MongoDB/MySQL credentials.
- TeamPCP claimed responsibility for the March 23 breach that tampered with two GitHub Actions workflows and two Open VSX plugins to inject a credential‑stealer.
- KICS Docker image and two VS Code extensions were also compromised, briefly affecting the Bitwarden CLI npm package.
Why it matters: The leak exposes source code, employee records, API keys and database credentials, putting Checkmarx’s internal assets at risk and potentially exposing any services that use those credentials, while forcing the firm to lock down the repo and promise customer notifications if personal data is involved.



