Featured
KL Rahul, IPL 2026, Delhi Capitals, highest IPL score Indian, Punjab Kings vs DC
KL Rahul shows textbook cricket still rules IPL as he smashes record 152* vs Punjab Kings
4, 4, 4, 4, 4, 4! Prabhsimran Singh punishes Mukesh Kumar in explosive IPL 2026 blitz
Prabhsimran Singh, DC vs PBKS, IPL 2026, Punjab Kings vs Delhi Capitals, IPL records
6 Fours in One Over! Prabhsimran Singh Joins Elite IPL Record List
April 25, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Search the Site
Popular Searches:
Chatgpt Nasa Halloween
Recent Posts
Nehal Wadhera
Nehal Wadhera Biography – Punjab Kings Young Left-Handed Batter | IPL 2026 Rising Star
April 25, 2026
PBKS vs DC IPL 2026 Result: Punjab Kings Chase Down 265 to Beat Delhi Capitals by 6 Wickets in Record Win
April 25, 2026
PBKS vs DC IPL 2026: Prabhsimran Singh and Shreyas Iyer Fifties Power Punjab Kings to Record 265 Chase Against Delhi Capitals
April 25, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Follow us
Home/Technology/Checkmarx hit again, popular tools spreading credential-stealing malware
Technology

Checkmarx hit again, popular tools spreading credential-stealing malware

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular...

Santhosh Kumar
April 25, 2026 2 Min Read

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular distribution channels including Docker Hub and VS Code extensions, raising serious concerns about software supply chain security and developer trust in open-source ecosystems.

Table Of Content

  • Malware found in widely used developer tools
  • Credential theft and data exfiltration risks
  • Supply chain impact and developer exposure
  • Ongoing supply chain attack campaign

Malware found in widely used developer tools

Security researchers revealed that malicious code was inserted into Checkmarx’s KICS (Keeping Infrastructure as Code Secure) Docker images and VS Code extensions. The infected versions were uploaded using existing trusted tags such as v2.1.20 and latest, meaning developers unknowingly downloaded compromised builds instead of safe ones. Since KICS is downloaded millions of times for infrastructure security scanning, the impact could potentially be widespread across development environments.

Credential theft and data exfiltration risks

The injected malware is designed to steal sensitive developer and cloud credentials, including GitHub tokens, AWS and Azure credentials, Google Cloud access data, SSH keys, and environment variables. It then encrypts and exfiltrates the stolen information to attacker-controlled systems. In some cases, it even pushes stolen data into public repositories under victim accounts, increasing the risk of further exploitation and secondary attacks.

Supply chain impact and developer exposure

Checkmarx tools are widely used in CI/CD pipelines to scan infrastructure-as-code files like Terraform, Kubernetes, and CloudFormation. Security experts warn that any secrets exposed during scans should now be considered compromised. Developers are being urged to rotate credentials, audit GitHub repositories, review npm packages, and check cloud logs for unusual activity as part of incident response measures.

Ongoing supply chain attack campaign

Security analysts suggest the attack may be linked to a threat group known as TeamPCP, which has been targeting software supply chains across ecosystems like GitHub, npm, PyPI, Docker Hub, and OpenVSX since late 2025. This campaign has previously affected other major developer tools, highlighting a growing trend of attackers focusing on trusted open-source infrastructure to spread malware at scale.

Tags:

CheckmarxCredential TheftDocker HubMalwareSupply Chain Attack

Share Article

AAP ticket for cash Surat, the blunt times
Previous Post

Ticket-for-Cash Row Rocks AAP in Surat Before Civic Polls

Shrimad Rajchandra hospital Physiological cord clamping research India, the blunt times
Next Post

Shrimad Rajchandra hospital’s Cord Clamping Research Gets Global Recognition

Picked
KL Rahul, Nitish Rana, DC vs PBKS 2026, IPL partnerships, Arun Jaitley Stadium
KL Rahul, Nitish Rana power DC with 220-run stand as Delhi Capitals post 264/2 vs Punjab Kings in IPL 2026
KL Rahul, IPL 2026, Delhi Capitals, highest IPL score Indian, Punjab Kings vs DC
KL Rahul shows textbook cricket still rules IPL as he smashes record 152* vs Punjab Kings
4, 4, 4, 4, 4, 4! Prabhsimran Singh punishes Mukesh Kumar in explosive IPL 2026 blitz
Prabhsimran Singh, DC vs PBKS, IPL 2026, Punjab Kings vs Delhi Capitals, IPL records
6 Fours in One Over! Prabhsimran Singh Joins Elite IPL Record List
Getafe vs Barcelona
Getafe vs Barcelona: Kick-off Time, Where to Watch, and La Liga Match Preview
Chicago Cubs vs Los Angeles Dodgers Live Stream:
Chicago Cubs vs Los Angeles Dodgers Live Stream: How to Watch MLB Game Tonight
Popular Posts
Getafe vs Barcelona
Getafe vs Barcelona: Kick-off Time, Where to Watch, and La Liga Match Preview
By Santhosh Kumar
Chicago Cubs vs Los Angeles Dodgers Live Stream:
Chicago Cubs vs Los Angeles Dodgers Live Stream: How to Watch MLB Game Tonight
By Santhosh Kumar
Delhi Capitals vs Punjab Kings Live Score, IPL 2026: KL Rahul smashed a 47-ball century against PBKS.
By Santhosh Kumar
dc vs pbks
DC vs PBKS IPL 2026: Lungi Ngidi Injury Halts Match at Arun Jaitley Stadium | Delhi Capitals vs Punjab Kings Live Updates, Scorecard, Stats & Highlights
By Santhosh Kumar
"Line of Control", a powerful cinematic adaptation of internationally acclaimed novel The Collaborator-PNn
“Line of Control”, a powerful cinematic adaptation of internationally acclaimed novel The Collaborator
By TBT Online Desk
Concept Medical -PNN
Concept Medical Highlights What Happens After the First Year
By TBT Online Desk

Read Next

US–China AI race heats up as DeepSeek V4 launches on Huawei chips instead of Nvidia
Technology
US–China AI race heats up as DeepSeek V4 launches on Huawei chips instead of Nvidia
April 25, 2026
2 Min Read
Meta slashes 8,000 jobs as Microsoft offers buyouts amid AI-driven restructuring
Technology
Meta slashes 8,000 jobs as Microsoft offers buyouts amid AI-driven restructuring
April 25, 2026
2 Min Read
OpenAI treats healthcare with new ChatGPT for clinicians
Technology
OpenAI treats healthcare with new ChatGPT for clinicians
April 25, 2026
2 Min Read
WhatsApp lets users recharge Jio and Airtel
Technology
WhatsApp lets users recharge Jio and Airtel plans while chatting, but only for prepaid users
April 25, 2026
2 Min Read
The Blunt Times

The Blunt Times is a 24-hour news portal from Surat and south Gujarat. It was launched by senior journalist Melvyn Thomas, who has over 21 years of experience working with the top news organizations such as The Indian Express, The Times of India, and The Economic Times.

Popular
KL Rahul, Nitish Rana power DC with 220-run stand as Delhi Capitals post 264/2 vs Punjab Kings in IPL 2026
April 25, 2026
KL Rahul shows textbook cricket still rules IPL as he smashes record 152* vs Punjab Kings
April 25, 2026
4, 4, 4, 4, 4, 4! Prabhsimran Singh punishes Mukesh Kumar in explosive IPL 2026 blitz
April 25, 2026
6 Fours in One Over! Prabhsimran Singh Joins Elite IPL Record List
April 25, 2026
Categories
City Events
National
Business Vibes
Lifestyle
Spotlight
Regional
Education
Entertainment
Health
Press Release
Trending
Sports

© 2026 All Rights Reserved, The Blunt Times

  • Terms of Service
  • Privacy Policy