Featured
Mission Five Million Trees Ahmedabad, the blunt times
Ahmedabad Targets 50 Lakh Trees Under Mega Green Mission
Recycled polyester fibre in Indian textile industry, the blunt times
Iran Conflict Sparks Green Shift in India’s Textile Industry
Metas Adventist College Graduation Ceremony, the blunt times
Metas Adventist College celebrates 21st graduation ceremony
June 5, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Search the Site
Popular Searches:
Chatgpt Nasa Halloween
Recent Posts
Eco Parkside
Eco Parkside Strengthens Community Spirit Through Parkside Premier League Season 2.0
June 5, 2026
Ajay’s Café
Ajay’s Café Bags ‘Leading Café Chain of the Year’, Reinforces Growth Leadership
June 5, 2026
PM Modi Surat speech Congress attack, the blunt times
Gujarat : PM Modi Launches Sharp Attack on Congress in Surat, Pushes Green Growth Vision
June 5, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Follow us
Home/Technology/Checkmarx hit again, popular tools spreading credential-stealing malware
Technology

Checkmarx hit again, popular tools spreading credential-stealing malware

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular...

Santhosh Kumar
April 25, 2026 2 Min Read

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular distribution channels including Docker Hub and VS Code extensions, raising serious concerns about software supply chain security and developer trust in open-source ecosystems.

Table Of Content

  • Malware found in widely used developer tools
  • Credential theft and data exfiltration risks
  • Supply chain impact and developer exposure
  • Ongoing supply chain attack campaign

Malware found in widely used developer tools

Security researchers revealed that malicious code was inserted into Checkmarx’s KICS (Keeping Infrastructure as Code Secure) Docker images and VS Code extensions. The infected versions were uploaded using existing trusted tags such as v2.1.20 and latest, meaning developers unknowingly downloaded compromised builds instead of safe ones. Since KICS is downloaded millions of times for infrastructure security scanning, the impact could potentially be widespread across development environments.

Credential theft and data exfiltration risks

The injected malware is designed to steal sensitive developer and cloud credentials, including GitHub tokens, AWS and Azure credentials, Google Cloud access data, SSH keys, and environment variables. It then encrypts and exfiltrates the stolen information to attacker-controlled systems. In some cases, it even pushes stolen data into public repositories under victim accounts, increasing the risk of further exploitation and secondary attacks.

Supply chain impact and developer exposure

Checkmarx tools are widely used in CI/CD pipelines to scan infrastructure-as-code files like Terraform, Kubernetes, and CloudFormation. Security experts warn that any secrets exposed during scans should now be considered compromised. Developers are being urged to rotate credentials, audit GitHub repositories, review npm packages, and check cloud logs for unusual activity as part of incident response measures.

Ongoing supply chain attack campaign

Security analysts suggest the attack may be linked to a threat group known as TeamPCP, which has been targeting software supply chains across ecosystems like GitHub, npm, PyPI, Docker Hub, and OpenVSX since late 2025. This campaign has previously affected other major developer tools, highlighting a growing trend of attackers focusing on trusted open-source infrastructure to spread malware at scale.

Tags:

CheckmarxCredential TheftDocker HubMalwareSupply Chain Attack

Share Article

AAP ticket for cash Surat, the blunt times
Previous Post

Ticket-for-Cash Row Rocks AAP in Surat Before Civic Polls

Shrimad Rajchandra hospital Physiological cord clamping research India, the blunt times
Next Post

Shrimad Rajchandra hospital’s Cord Clamping Research Gets Global Recognition

Picked
Lokhande Industries
Lokhande Industries Reports 164% Per-Person Profit Growth After Joining Hands with Dr. Vivek Bindra and Bada Business Private Limited
Mission Five Million Trees Ahmedabad, the blunt times
Ahmedabad Targets 50 Lakh Trees Under Mega Green Mission
Recycled polyester fibre in Indian textile industry, the blunt times
Iran Conflict Sparks Green Shift in India’s Textile Industry
Metas Adventist College Graduation Ceremony, the blunt times
Metas Adventist College celebrates 21st graduation ceremony
Satyukt Analytics Introduces Patented Satellite-Based Nitrogen Estimation Technology, Supporting Precision Nutrient Management for Over 1 Lakh Farmers-TBT
Satyukt Analytics Introduces Patented Satellite-Based Nitrogen Estimation Technology, Supporting Precision Nutrient Management for Over 1 Lakh Farmers
Gujarat Regional Science Centres, the blunt times
Gujarat’s Science Revolution Reaches Millions as Regional Science Centres Become Hubs of Innovation
Popular Posts
Satyukt Analytics Introduces Patented Satellite-Based Nitrogen Estimation Technology, Supporting Precision Nutrient Management for Over 1 Lakh Farmers-TBT
Satyukt Analytics Introduces Patented Satellite-Based Nitrogen Estimation Technology, Supporting Precision Nutrient Management for Over 1 Lakh Farmers
By TBT Online Desk
Gujarat Regional Science Centres, the blunt times
Gujarat’s Science Revolution Reaches Millions as Regional Science Centres Become Hubs of Innovation
By Times News Network
IIT Gandhinagar hydrogel for wastewater treatment, the blunt times
Gujarat :  IIT Gandhinagar Scientists Develop ‘Super Sponge’ to Tackle Toxic Industrial Wastewater
By Times News Network
Ashok Jirawala SGCCI President, the blunt times
Ashok Jirawala to Lead SGCCI as New President
By Times News Network
ED drug syndicate raids Gujarat, the blunt times
BREAKING NEWS : ED Targets Drug Mafia Network in Gujarat, Mumbai Raids
By Times News Network
Chiripal Poly Films fire rescue team, the blunt times
Chiripal Team Prevents Major Fire Near Bareja Plant
By Times News Network

Read Next

Shiprocket
Technology
Shiprocket SHIVIR 2026 Is Coming to Mumbai, and India’s Commerce Builders Are Already Talking
June 1, 2026
2 Min Read
BharathCloud
Technology
BharathCloud, BDIA Leaders Discuss India’s AI-Ready Digital Infrastructure Future
May 30, 2026
3 Min Read
Technology
Definable AI Is Building Reliable AI Agents for the Businesses the AI Boom Left Behind
May 29, 2026
2 Min Read
Jitendra Vaswani
Technology
“The Window to Adapt Is Closing”: Jitendra Vaswani on AI and the Future of Jobs
May 22, 2026
4 Min Read
The Blunt Times

The Blunt Times is a 24-hour news portal from Surat and south Gujarat. It was launched by senior journalist Melvyn Thomas, who has over 21 years of experience working with the top news organizations such as The Indian Express, The Times of India, and The Economic Times.

Popular
Lokhande Industries Reports 164% Per-Person Profit Growth After Joining Hands with Dr. Vivek Bindra and Bada Business Private Limited
June 5, 2026
Ahmedabad Targets 50 Lakh Trees Under Mega Green Mission
June 5, 2026
Iran Conflict Sparks Green Shift in India’s Textile Industry
June 5, 2026
Metas Adventist College celebrates 21st graduation ceremony
June 5, 2026
Categories
City Events
National
Business Vibes
Lifestyle
Spotlight
Regional
Education
Entertainment
Health
Press Release
Trending
Sports

© 2026 All Rights Reserved, The Blunt Times

  • Terms of Service
  • Privacy Policy