Featured
Celebrities
Indian Celebrities Turning Over a New Leaf
SEPC
Major Relief for SEPC as Madras High Court Lifts Attachment on Rs 154 Crore Receivables Following Dispute Settlement
FutureMe
Experience the transformative power of ‘liquid gold’: FutureMe’s Arayani Nourishing Face Oil
October 6, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Search the Site
Popular Searches:
Chatgpt Nasa Halloween
Recent Posts
Armour
The Armour Strength opens second branch in Ahmedabad, plans 25 gyms in five years
October 6, 2026
Jeevan Prasad Swami: Cyber Security Awareness Session at PM SHRI Chhapura Kalan, Students Receive Guidance for a Safer Digital Future
Jeevan Prasad Swami: Cyber Security Awareness Session at PM SHRI Chhapura Kalan, Students Receive Guidance for a Safer Digital Future
October 6, 2026
Family
Family Office or Wealth Management Consultant
October 6, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Follow us
Home/Technology/Checkmarx hit again, popular tools spreading credential-stealing malware
Technology

Checkmarx hit again, popular tools spreading credential-stealing malware

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular...

Santhosh Kumar
April 25, 2026 2 Min Read

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular distribution channels including Docker Hub and VS Code extensions, raising serious concerns about software supply chain security and developer trust in open-source ecosystems.

Malware found in widely used developer tools

Security researchers revealed that malicious code was inserted into Checkmarx’s KICS (Keeping Infrastructure as Code Secure) Docker images and VS Code extensions. The infected versions were uploaded using existing trusted tags such as v2.1.20 and latest, meaning developers unknowingly downloaded compromised builds instead of safe ones. Since KICS is downloaded millions of times for infrastructure security scanning, the impact could potentially be widespread across development environments.

Credential theft and data exfiltration risks

The injected malware is designed to steal sensitive developer and cloud credentials, including GitHub tokens, AWS and Azure credentials, Google Cloud access data, SSH keys, and environment variables. It then encrypts and exfiltrates the stolen information to attacker-controlled systems. In some cases, it even pushes stolen data into public repositories under victim accounts, increasing the risk of further exploitation and secondary attacks.

Supply chain impact and developer exposure

Checkmarx tools are widely used in CI/CD pipelines to scan infrastructure-as-code files like Terraform, Kubernetes, and CloudFormation. Security experts warn that any secrets exposed during scans should now be considered compromised. Developers are being urged to rotate credentials, audit GitHub repositories, review npm packages, and check cloud logs for unusual activity as part of incident response measures.

Ongoing supply chain attack campaign

Security analysts suggest the attack may be linked to a threat group known as TeamPCP, which has been targeting software supply chains across ecosystems like GitHub, npm, PyPI, Docker Hub, and OpenVSX since late 2025. This campaign has previously affected other major developer tools, highlighting a growing trend of attackers focusing on trusted open-source infrastructure to spread malware at scale.

Tags:

CheckmarxCredential TheftDocker HubMalwareSupply Chain Attack

Share Article

AAP ticket for cash Surat, the blunt times
Previous Post

Ticket-for-Cash Row Rocks AAP in Surat Before Civic Polls

Shrimad Rajchandra hospital Physiological cord clamping research India, the blunt times
Next Post

Shrimad Rajchandra hospital’s Cord Clamping Research Gets Global Recognition

Picked
Dr. Dipti Deepak Patel Takes Charge as IMA Surat President for 2026–27-TBT
Dr. Dipti Deepak Patel Takes Charge as IMA Surat President for 2026–27
Celebrities
Indian Celebrities Turning Over a New Leaf
SEPC
Major Relief for SEPC as Madras High Court Lifts Attachment on Rs 154 Crore Receivables Following Dispute Settlement
FutureMe
Experience the transformative power of ‘liquid gold’: FutureMe’s Arayani Nourishing Face Oil
GJEPC UNNATI women in gems and jewellery, the blunt times
GJEPC Launches UNNATI for Women in Gems & Jewellery
India’s Branded Residences Pipeline Reaches 46 Projects Across 18 Cities, as TBRS 2.0 Opens in Mumbai
India’s Branded Residences Pipeline Reaches 46 Projects Across 18 Cities, as TBRS 2.0 Opens in Mumbai
Popular Posts
GJEPC UNNATI women in gems and jewellery, the blunt times
GJEPC Launches UNNATI for Women in Gems & Jewellery
By Times News Service
India’s Branded Residences Pipeline Reaches 46 Projects Across 18 Cities, as TBRS 2.0 Opens in Mumbai
India’s Branded Residences Pipeline Reaches 46 Projects Across 18 Cities, as TBRS 2.0 Opens in Mumbai
By TBT Online Desk
Vadodara
Vadodara’s New Era Senior Secondary School Becomes Gujarat’s First School to Receive QS I-GAUGE Diamond Rating
By TBT Online Desk
Ayurvedic
Ayurvedic Panchakarma at Parul Ayurved Hospital’s Madhavbaug Unit Supports Patients on Their Cardiac Care Journeys
By TBT Online Desk
Parul University
Parul University Makes Global Debut in Times Higher Education World University Rankings 2027, Becomes Only University from Gujarat to Enter Global Rankings
By TBT Online Desk
SMMPanelServer
SMMPanelServer Review: An SMM Panel Built for Resellers
By TBT Online Desk

Read Next

SMMPanelServer
Technology
SMMPanelServer Review: An SMM Panel Built for Resellers
October 5, 2026
5 Min Read
Food Wastage
Technology
How Is an App Helping Universities Reduce Food Wastage?
October 3, 2026
2 Min Read
Google Apps Script Abuse: Phishing, Fraud, Malware and CSAM Risks Identified in TraceX Labs Report
Technology
Google Apps Script Abuse: Phishing, Fraud, Malware and CSAM Risks Identified in TraceX Labs Report
September 30, 2026
4 Min Read
Abuse of Google Apps Script Web Apps Trusted Cloud Infrastructure Abuse
Technology
TraceX Labs Report Highlights Google Apps Script Abuse for Phishing, Malware and SEO Spam
September 30, 2026
4 Min Read
The Blunt Times

The Blunt Times is a 24-hour news portal from Surat and south Gujarat. It was launched by senior journalist Melvyn Thomas, who has over 21 years of experience working with the top news organizations such as The Indian Express, The Times of India, and The Economic Times.

Popular
Dr. Dipti Deepak Patel Takes Charge as IMA Surat President for 2026–27
October 5, 2026
Indian Celebrities Turning Over a New Leaf
October 5, 2026
Major Relief for SEPC as Madras High Court Lifts Attachment on Rs 154 Crore Receivables Following Dispute Settlement
October 5, 2026
Experience the transformative power of ‘liquid gold’: FutureMe’s Arayani Nourishing Face Oil
October 5, 2026
Categories
City Events
National
Business Vibes
Lifestyle
Business
Education
Entertainment
Spotlight
Regional
Health
Press Release
Sports

© 2026 All Rights Reserved, The Blunt Times

  • Terms of Service
  • Privacy Policy