Featured
Haror
Dr. Haror’s Wellness Hits a Milestone with 20,000+ Successful Hair Transplant Procedures
Aastha Spintex Stock price up 10% on Rs. 51.46 crore order book for Falcon Yarns-TBT
Aastha Spintex Stock price up 10% on Rs. 51.46 crore order book for Falcon Yarns
Emirates Film Festival honours Gaganpreet Singh for advancing international cinema across the Gulf
Emirates Film Festival honours Gaganpreet Singh for advancing international cinema across the Gulf
August 5, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Search the Site
Popular Searches:
Chatgpt Nasa Halloween
Recent Posts
California-Based AI Company Webenoid Is Building the World’s Largest Remote AI Internship Ecosystem
August 5, 2026
Ajay’s Cafe
Friendship Day Drives Record Consumption at Ajay’s Cafe with 89% Jump in Cold Coffee Sales
August 5, 2026
Agarwal Toughened Glass India Limited Q1 FY27 Business Update, Revenue grows ~23% QoQ to ₹ 34.40 Crores-TBT
Agarwal Toughened Glass India Limited Q1 FY27 Business Update, Revenue grows ~23% QoQ to ₹ 34.40 Crores
August 5, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Follow us
Home/Technology/Checkmarx hit again, popular tools spreading credential-stealing malware
Technology

Checkmarx hit again, popular tools spreading credential-stealing malware

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular...

Santhosh Kumar
April 25, 2026 2 Min Read

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular distribution channels including Docker Hub and VS Code extensions, raising serious concerns about software supply chain security and developer trust in open-source ecosystems.

Malware found in widely used developer tools

Security researchers revealed that malicious code was inserted into Checkmarx’s KICS (Keeping Infrastructure as Code Secure) Docker images and VS Code extensions. The infected versions were uploaded using existing trusted tags such as v2.1.20 and latest, meaning developers unknowingly downloaded compromised builds instead of safe ones. Since KICS is downloaded millions of times for infrastructure security scanning, the impact could potentially be widespread across development environments.

Credential theft and data exfiltration risks

The injected malware is designed to steal sensitive developer and cloud credentials, including GitHub tokens, AWS and Azure credentials, Google Cloud access data, SSH keys, and environment variables. It then encrypts and exfiltrates the stolen information to attacker-controlled systems. In some cases, it even pushes stolen data into public repositories under victim accounts, increasing the risk of further exploitation and secondary attacks.

Supply chain impact and developer exposure

Checkmarx tools are widely used in CI/CD pipelines to scan infrastructure-as-code files like Terraform, Kubernetes, and CloudFormation. Security experts warn that any secrets exposed during scans should now be considered compromised. Developers are being urged to rotate credentials, audit GitHub repositories, review npm packages, and check cloud logs for unusual activity as part of incident response measures.

Ongoing supply chain attack campaign

Security analysts suggest the attack may be linked to a threat group known as TeamPCP, which has been targeting software supply chains across ecosystems like GitHub, npm, PyPI, Docker Hub, and OpenVSX since late 2025. This campaign has previously affected other major developer tools, highlighting a growing trend of attackers focusing on trusted open-source infrastructure to spread malware at scale.

Tags:

CheckmarxCredential TheftDocker HubMalwareSupply Chain Attack

Share Article

AAP ticket for cash Surat, the blunt times
Previous Post

Ticket-for-Cash Row Rocks AAP in Surat Before Civic Polls

Shrimad Rajchandra hospital Physiological cord clamping research India, the blunt times
Next Post

Shrimad Rajchandra hospital’s Cord Clamping Research Gets Global Recognition

Picked
Cosmetic Dentistry
The Rise of Smile Makeovers: Why More Indians Are Investing in Cosmetic Dentistry
Haror
Dr. Haror’s Wellness Hits a Milestone with 20,000+ Successful Hair Transplant Procedures
Aastha Spintex Stock price up 10% on Rs. 51.46 crore order book for Falcon Yarns-TBT
Aastha Spintex Stock price up 10% on Rs. 51.46 crore order book for Falcon Yarns
Emirates Film Festival honours Gaganpreet Singh for advancing international cinema across the Gulf
Emirates Film Festival honours Gaganpreet Singh for advancing international cinema across the Gulf
Pride of Bharat
Pride of Bharat Leadership Summit 2026 Brings Together India’s Leading Changemakers
Nico Digital Drives Integrated Communications Strategy for Shyam Steel's Landmark Industrial Expansion in West Bengal-TBT
Nico Digital Drives Integrated Communications Strategy for Shyam Steel’s Landmark Industrial Expansion in West Bengal
Popular Posts
Pride of Bharat
Pride of Bharat Leadership Summit 2026 Brings Together India’s Leading Changemakers
By TBT Online Desk
Nico Digital Drives Integrated Communications Strategy for Shyam Steel's Landmark Industrial Expansion in West Bengal-TBT
Nico Digital Drives Integrated Communications Strategy for Shyam Steel’s Landmark Industrial Expansion in West Bengal
By TBT Online Desk
Sarigam pollution PIL, the blunt times
Gujarat HC to Hear Sarigam Pollution PIL on August 11
By Times News Network
Motorized Wheelchair Price in India: Complete Buying Guide, Features & Wheelchair Cost
Motorized Wheelchair Price in India: Complete Buying Guide, Features & Wheelchair Cost
By TBT Online Desk
Ahmedabad's Gaj-Aakriti Wins Gold at WOW Awards Asia 2026 for Wedding Storytelling
Ahmedabad’s Gaj-Aakriti Wins Gold at WOW Awards Asia 2026 for Wedding Storytelling
By TBT Online Desk
Bank of India Settles ₹71 Lakh Accident Insurance Claim for SRK Exports Employee's Family
Bank of India Settles ₹71 Lakh Accident Insurance Claim for SRK Exports Employee’s Family
By TBT Online Desk

Read Next

Technology
Microsoft Unveils MAI-Cyber-1-Flash AI Model for Cybersecurity, Claims 96% Benchmark Score
July 29, 2026
2 Min Read
Technology
AMD Releases Adrenalin 26.7.1 WHQL Drivers With Radeon RX 9050 Support
July 29, 2026
2 Min Read
Technology
Apple Upgrade: 20 Things You Should Know Before Leasing an iPhone, iPad, or Mac
July 29, 2026
2 Min Read
Search Router-PNn
Technology
Search Router Launches Search API in India to Help AI Agents Access Real-Time Web Information
July 24, 2026
3 Min Read
The Blunt Times

The Blunt Times is a 24-hour news portal from Surat and south Gujarat. It was launched by senior journalist Melvyn Thomas, who has over 21 years of experience working with the top news organizations such as The Indian Express, The Times of India, and The Economic Times.

Popular
The Rise of Smile Makeovers: Why More Indians Are Investing in Cosmetic Dentistry
August 5, 2026
Dr. Haror’s Wellness Hits a Milestone with 20,000+ Successful Hair Transplant Procedures
August 5, 2026
Aastha Spintex Stock price up 10% on Rs. 51.46 crore order book for Falcon Yarns
August 5, 2026
Emirates Film Festival honours Gaganpreet Singh for advancing international cinema across the Gulf
August 5, 2026
Categories
City Events
National
Business Vibes
Lifestyle
Business
Spotlight
Education
Regional
Entertainment
Health
Press Release
Sports

© 2026 All Rights Reserved, The Blunt Times

  • Terms of Service
  • Privacy Policy