Featured
St. George’s University Announces August Intake for Indian Students-TBT
St. George’s University Announces August Intake for Indian Students
TradeFlock-PNN
TradeFlock Launches List of the Best Education Leaders in India 2026
TradeFlock-PNN
TradeFlock Releases the List of the Best Tech Leaders in India 2026
June 25, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Search the Site
Popular Searches:
Chatgpt Nasa Halloween
Recent Posts
Surat green textile diamond industry Norway partnership, the blunt times
Developed India-2047: Surat Emerges as Key Hub in India–Norway Green Industrial Partnership
June 25, 2026
Adani Ports S&P upgrade BBB rating, the blunt times
S&P Upgrades Adani Ports to BBB, Citing Strong Cash Flow and Growth Outlook
June 25, 2026
Adani Airport City integrated airport cities India, the blunt times
Adani Airport City Unveils Rs.20,000 Crore Integrated Airport Cities Across India
June 25, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Follow us
Home/Technology/Checkmarx hit again, popular tools spreading credential-stealing malware
Technology

Checkmarx hit again, popular tools spreading credential-stealing malware

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular...

Santhosh Kumar
April 25, 2026 2 Min Read

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular distribution channels including Docker Hub and VS Code extensions, raising serious concerns about software supply chain security and developer trust in open-source ecosystems.

Table Of Content

  • Malware found in widely used developer tools
  • Credential theft and data exfiltration risks
  • Supply chain impact and developer exposure
  • Ongoing supply chain attack campaign

Malware found in widely used developer tools

Security researchers revealed that malicious code was inserted into Checkmarx’s KICS (Keeping Infrastructure as Code Secure) Docker images and VS Code extensions. The infected versions were uploaded using existing trusted tags such as v2.1.20 and latest, meaning developers unknowingly downloaded compromised builds instead of safe ones. Since KICS is downloaded millions of times for infrastructure security scanning, the impact could potentially be widespread across development environments.

Credential theft and data exfiltration risks

The injected malware is designed to steal sensitive developer and cloud credentials, including GitHub tokens, AWS and Azure credentials, Google Cloud access data, SSH keys, and environment variables. It then encrypts and exfiltrates the stolen information to attacker-controlled systems. In some cases, it even pushes stolen data into public repositories under victim accounts, increasing the risk of further exploitation and secondary attacks.

Supply chain impact and developer exposure

Checkmarx tools are widely used in CI/CD pipelines to scan infrastructure-as-code files like Terraform, Kubernetes, and CloudFormation. Security experts warn that any secrets exposed during scans should now be considered compromised. Developers are being urged to rotate credentials, audit GitHub repositories, review npm packages, and check cloud logs for unusual activity as part of incident response measures.

Ongoing supply chain attack campaign

Security analysts suggest the attack may be linked to a threat group known as TeamPCP, which has been targeting software supply chains across ecosystems like GitHub, npm, PyPI, Docker Hub, and OpenVSX since late 2025. This campaign has previously affected other major developer tools, highlighting a growing trend of attackers focusing on trusted open-source infrastructure to spread malware at scale.

Tags:

CheckmarxCredential TheftDocker HubMalwareSupply Chain Attack

Share Article

AAP ticket for cash Surat, the blunt times
Previous Post

Ticket-for-Cash Row Rocks AAP in Surat Before Civic Polls

Shrimad Rajchandra hospital Physiological cord clamping research India, the blunt times
Next Post

Shrimad Rajchandra hospital’s Cord Clamping Research Gets Global Recognition

Picked
Sachin Industrial Society new building Surat, the blunt times
Sachin Industrial Society Inaugurates New Rs.2.5 Crore Corporate-Style Building
St. George’s University Announces August Intake for Indian Students-TBT
St. George’s University Announces August Intake for Indian Students
TradeFlock-PNN
TradeFlock Launches List of the Best Education Leaders in India 2026
TradeFlock-PNN
TradeFlock Releases the List of the Best Tech Leaders in India 2026
Surat car rally controversy UP MLA, the blunt times
Surat Car Rally Sparks Law & Order Questions During UP MLA Visit
IMS-PNn
IMS Ghaziabad (University Courses Campus) Inaugurates IMS Today Studio, Strengthening Experiential Learning in Media Education
Popular Posts
Surat car rally controversy UP MLA, the blunt times
Surat Car Rally Sparks Law & Order Questions During UP MLA Visit
By Times News Network
IMS-PNn
IMS Ghaziabad (University Courses Campus) Inaugurates IMS Today Studio, Strengthening Experiential Learning in Media Education
By TBT Online Desk
Indian Army Launches Official Instagram Fact Check Account to Counter Deepfakes and Misinformation
By Santhosh Kumar
How Varun Singh Built India's Most Trusted Immigration Advisory Firm Over 17 Years-TBT
How Varun Singh Built India’s Most Trusted Immigration Advisory Firm Over 17 Years
By TBT Online Desk
Quantum Canvas-PNn
Quantum Canvas: India’s First UV Immersive Fine Art Exhibition Opens on 25 June’26
By TBT Online Desk
Ayeesha Aiman: From Topping the Aeronautical Engineering Entrance Exam to Miss India and Her Powerful Acting Journey in Inspector Avinash-TBT
Ayeesha Aiman: From Topping the Aeronautical Engineering Entrance Exam to Miss India and Her Powerful Acting Journey in Inspector Avinash
By TBT Online Desk

Read Next

From Chatbots To Cardiac Signals: Scanbo’s Ashissh Raichura On India’s Next Health AI Test-TBT
Technology
From Chatbots To Cardiac Signals: Scanbo’s Ashissh Raichura On India’s Next Health AI Test
June 25, 2026
5 Min Read
Technology
OpenAI Launches ‘Jalapeño,’ Its First Custom AI Chip Developed with Broadcom
June 24, 2026
1 Min Read
FUJIFILM -PNn
Technology
FUJIFILM India Introduces X-T30 III, Blending Technology and Creativity Through So City Collaboration
June 23, 2026
2 Min Read
Technology
As John Ternus Gains Influence at Apple, Focus Turns to Design Revival and Major Product Plans
June 21, 2026
2 Min Read
The Blunt Times

The Blunt Times is a 24-hour news portal from Surat and south Gujarat. It was launched by senior journalist Melvyn Thomas, who has over 21 years of experience working with the top news organizations such as The Indian Express, The Times of India, and The Economic Times.

Popular
Sachin Industrial Society Inaugurates New Rs.2.5 Crore Corporate-Style Building
June 25, 2026
St. George’s University Announces August Intake for Indian Students
June 25, 2026
TradeFlock Launches List of the Best Education Leaders in India 2026
June 25, 2026
TradeFlock Releases the List of the Best Tech Leaders in India 2026
June 25, 2026
Categories
City Events
National
Business Vibes
Lifestyle
Spotlight
Education
Regional
Entertainment
Health
Business
Press Release
Sports

© 2026 All Rights Reserved, The Blunt Times

  • Terms of Service
  • Privacy Policy