Featured
Hazoor Multi Projects Bags Rs. 193.85 Crore NHAI Contract for Toll Fee Collection in Tamil Nadu-TBT
Hazoor Multi Projects Bags Rs. 193.85 Crore NHAI Contract for Toll Fee Collection in Tamil Nadu
Ratul Puri on the Changing Landscape of India’s Energy Future-TBT
Ratul Puri on the Changing Landscape of India’s Energy Future
Adani Foundation AVPN Global Conference 2026, the blunt times
Adani Foundation Hosts AVPN Welcome Dinner in Delhi
August 26, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Search the Site
Popular Searches:
Chatgpt Nasa Halloween
Recent Posts
Kidvento
Nine Years of Reinvention: How Kidvento Built Ulipsu and an Ecosystem of Future-Ready Learning
August 26, 2026
Navinmart
MY FM Excellence Awards 2026 Honours Navinmart for Excellence in E-Commerce
August 26, 2026
Mukesh Mahalinga
Odisha Health Minister Dr. Mukesh Mahalinga visits Sri Sathya Sai Heart Hospital
August 26, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Follow us
Home/Technology/Checkmarx hit again, popular tools spreading credential-stealing malware
Technology

Checkmarx hit again, popular tools spreading credential-stealing malware

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular...

Santhosh Kumar
April 25, 2026 2 Min Read

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular distribution channels including Docker Hub and VS Code extensions, raising serious concerns about software supply chain security and developer trust in open-source ecosystems.

Malware found in widely used developer tools

Security researchers revealed that malicious code was inserted into Checkmarx’s KICS (Keeping Infrastructure as Code Secure) Docker images and VS Code extensions. The infected versions were uploaded using existing trusted tags such as v2.1.20 and latest, meaning developers unknowingly downloaded compromised builds instead of safe ones. Since KICS is downloaded millions of times for infrastructure security scanning, the impact could potentially be widespread across development environments.

Credential theft and data exfiltration risks

The injected malware is designed to steal sensitive developer and cloud credentials, including GitHub tokens, AWS and Azure credentials, Google Cloud access data, SSH keys, and environment variables. It then encrypts and exfiltrates the stolen information to attacker-controlled systems. In some cases, it even pushes stolen data into public repositories under victim accounts, increasing the risk of further exploitation and secondary attacks.

Supply chain impact and developer exposure

Checkmarx tools are widely used in CI/CD pipelines to scan infrastructure-as-code files like Terraform, Kubernetes, and CloudFormation. Security experts warn that any secrets exposed during scans should now be considered compromised. Developers are being urged to rotate credentials, audit GitHub repositories, review npm packages, and check cloud logs for unusual activity as part of incident response measures.

Ongoing supply chain attack campaign

Security analysts suggest the attack may be linked to a threat group known as TeamPCP, which has been targeting software supply chains across ecosystems like GitHub, npm, PyPI, Docker Hub, and OpenVSX since late 2025. This campaign has previously affected other major developer tools, highlighting a growing trend of attackers focusing on trusted open-source infrastructure to spread malware at scale.

Tags:

CheckmarxCredential TheftDocker HubMalwareSupply Chain Attack

Share Article

AAP ticket for cash Surat, the blunt times
Previous Post

Ticket-for-Cash Row Rocks AAP in Surat Before Civic Polls

Shrimad Rajchandra hospital Physiological cord clamping research India, the blunt times
Next Post

Shrimad Rajchandra hospital’s Cord Clamping Research Gets Global Recognition

Picked
OpenAI Adds Custom Sticker Maker to ChatGPT: Create Personalised Stickers From Your Ideas
Hazoor Multi Projects Bags Rs. 193.85 Crore NHAI Contract for Toll Fee Collection in Tamil Nadu-TBT
Hazoor Multi Projects Bags Rs. 193.85 Crore NHAI Contract for Toll Fee Collection in Tamil Nadu
Ratul Puri on the Changing Landscape of India’s Energy Future-TBT
Ratul Puri on the Changing Landscape of India’s Energy Future
Adani Foundation AVPN Global Conference 2026, the blunt times
Adani Foundation Hosts AVPN Welcome Dinner in Delhi
Dr Sudhir Joshi Khardungla cycling expedition, the blunt times
63-Year-Old Valsad Doctor Cycles 502 Km to Khardungla
Money Expo India Gathers 1000+ NRI Investors In Mumbai-TBT
Money Expo India Gathers 1000+ NRI Investors In Mumbai
Popular Posts
Dr Sudhir Joshi Khardungla cycling expedition, the blunt times
63-Year-Old Valsad Doctor Cycles 502 Km to Khardungla
By Times News Network
Money Expo India Gathers 1000+ NRI Investors In Mumbai-TBT
Money Expo India Gathers 1000+ NRI Investors In Mumbai
By TBT Online Desk
IMS Ghaziabad
IMS Ghaziabad (University Courses Campus) Concludes 10-Day International FDP on Global Pedagogical Excellence and Research Leadership
By TBT Online Desk
Jitendra Vaswani
From Affiliate Marketing to AI SEO: Jitendra Vaswani’s Inside A Hustler’s Brain Explores the New Rules of Digital Growth
By TBT Online Desk
Hafele
Hafele Kabi-Flow Redefines Access and Security for Modern Furniture
By TBT Online Desk
CineNow
CineNow Unveils Leadership and Governance Structure for US$150 Million Film Investment Vehicle Invites Collaboration from the Indian Film Fraternity
By TBT Online Desk

Read Next

Technology
OpenAI’s Jalapeño AI Chip Targets Nvidia With Faster, More Efficient AI Inference
August 26, 2026
2 Min Read
Technology
OpenAI Adds Custom Sticker Maker to ChatGPT: Create Personalised Stickers From Your Ideas
August 26, 2026
2 Min Read
Technology
Tesla Recalls Nearly 3 Million Cars in China Over Emergency Door Handle Risk
August 25, 2026
2 Min Read
Technology
Nvidia Puts Groq 3 LPX Into Full Production as AI Inference Demand Grows
August 25, 2026
2 Min Read
The Blunt Times

The Blunt Times is a 24-hour news portal from Surat and south Gujarat. It was launched by senior journalist Melvyn Thomas, who has over 21 years of experience working with the top news organizations such as The Indian Express, The Times of India, and The Economic Times.

Popular
OpenAI Adds Custom Sticker Maker to ChatGPT: Create Personalised Stickers From Your Ideas
August 26, 2026
Hazoor Multi Projects Bags Rs. 193.85 Crore NHAI Contract for Toll Fee Collection in Tamil Nadu
August 26, 2026
Ratul Puri on the Changing Landscape of India’s Energy Future
August 26, 2026
Adani Foundation Hosts AVPN Welcome Dinner in Delhi
August 26, 2026
Categories
City Events
National
Business Vibes
Lifestyle
Business
Education
Spotlight
Regional
Entertainment
Health
Press Release
Sports

© 2026 All Rights Reserved, The Blunt Times

  • Terms of Service
  • Privacy Policy