Featured
Fin Homes
Can Fin Homes Showcases ‘Project Tejas’, its Rs 296.95-Crore Enterprise Digital Transformation Programme
The Design Village, L’École de Design Nantes Atlantique Launch TNDV Dual Degree Programme Between India and France-TBT
The Design Village, L’École de Design Nantes Atlantique Launch TNDV Dual Degree Programme Between India and France
Parul University
Parul University Journalism Students Complete Six-Day Delhi Media Leadership Tour Across India’s Top Newsrooms
September 16, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Search the Site
Popular Searches:
Chatgpt Nasa Halloween
Recent Posts
Atul M. Bosamiya, Under the Banner of Atul India Movies, Produces First Gujarati Pan-India Film ‘Shri Kesari Nandan’-TBT
Atul M. Bosamiya, Under the Banner of Atul India Movies, Produces First Gujarati Pan-India Film ‘Shri Kesari Nandan’
September 15, 2026
Palladium Ahmedabad Brings Ishaara’s ‘Phulkari Patola’ to the City-TBT
Palladium Ahmedabad Brings Ishaara’s ‘Phulkari Patola’ to the City
September 15, 2026
Furlicks
Furlicks Goes from 6 to 22 SKUs: Fredun Pharmaceuticals Ltd. Accelerates Pet Wellness Expansion
September 15, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Follow us
Home/Technology/Checkmarx hit again, popular tools spreading credential-stealing malware
Technology

Checkmarx hit again, popular tools spreading credential-stealing malware

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular...

Santhosh Kumar
April 25, 2026 2 Min Read

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular distribution channels including Docker Hub and VS Code extensions, raising serious concerns about software supply chain security and developer trust in open-source ecosystems.

Malware found in widely used developer tools

Security researchers revealed that malicious code was inserted into Checkmarx’s KICS (Keeping Infrastructure as Code Secure) Docker images and VS Code extensions. The infected versions were uploaded using existing trusted tags such as v2.1.20 and latest, meaning developers unknowingly downloaded compromised builds instead of safe ones. Since KICS is downloaded millions of times for infrastructure security scanning, the impact could potentially be widespread across development environments.

Credential theft and data exfiltration risks

The injected malware is designed to steal sensitive developer and cloud credentials, including GitHub tokens, AWS and Azure credentials, Google Cloud access data, SSH keys, and environment variables. It then encrypts and exfiltrates the stolen information to attacker-controlled systems. In some cases, it even pushes stolen data into public repositories under victim accounts, increasing the risk of further exploitation and secondary attacks.

Supply chain impact and developer exposure

Checkmarx tools are widely used in CI/CD pipelines to scan infrastructure-as-code files like Terraform, Kubernetes, and CloudFormation. Security experts warn that any secrets exposed during scans should now be considered compromised. Developers are being urged to rotate credentials, audit GitHub repositories, review npm packages, and check cloud logs for unusual activity as part of incident response measures.

Ongoing supply chain attack campaign

Security analysts suggest the attack may be linked to a threat group known as TeamPCP, which has been targeting software supply chains across ecosystems like GitHub, npm, PyPI, Docker Hub, and OpenVSX since late 2025. This campaign has previously affected other major developer tools, highlighting a growing trend of attackers focusing on trusted open-source infrastructure to spread malware at scale.

Tags:

CheckmarxCredential TheftDocker HubMalwareSupply Chain Attack

Share Article

AAP ticket for cash Surat, the blunt times
Previous Post

Ticket-for-Cash Row Rocks AAP in Surat Before Civic Polls

Shrimad Rajchandra hospital Physiological cord clamping research India, the blunt times
Next Post

Shrimad Rajchandra hospital’s Cord Clamping Research Gets Global Recognition

Picked
Ryan Group
Ryan Group of Schools Hosts the 24th Indian Model United Nations in the Capital
Fin Homes
Can Fin Homes Showcases ‘Project Tejas’, its Rs 296.95-Crore Enterprise Digital Transformation Programme
The Design Village, L’École de Design Nantes Atlantique Launch TNDV Dual Degree Programme Between India and France-TBT
The Design Village, L’École de Design Nantes Atlantique Launch TNDV Dual Degree Programme Between India and France
Parul University
Parul University Journalism Students Complete Six-Day Delhi Media Leadership Tour Across India’s Top Newsrooms
Rahul Jain
Mr. Rahul Jain Honoured with Accountancy Excellence Award – 2026
Sudarshan Pharma
Sudarshan Pharma Says Proposed 9.5% Stake Acquisition in US Firm Under Due Diligence
Popular Posts
Rahul Jain
Mr. Rahul Jain Honoured with Accountancy Excellence Award – 2026
By TBT Online Desk
Sudarshan Pharma
Sudarshan Pharma Says Proposed 9.5% Stake Acquisition in US Firm Under Due Diligence
By TBT Online Desk
₹711 crore Tapi-Karjan water project Gujarat, the blunt times
Gujarat : Rs.711 crore water project faces land acquisition questions
By Times News Network
Surat Ring Road potholes, the blunt times
Surat’s ‘Moon Driving’ Nightmare: Crater-Like Potholes Hit Textile Hub
By Times News Network
REHAU
REHAU Opens Second House of REHAU in Bengaluru, Bringing Its Complete Interior Solutions Experience Under One Roof
By TBT Online Desk
MarketWolf
MarketWolf partners with Appreciate to offer US stocks and global markets access to Indian investors via GIFT City
By TBT Online Desk

Read Next

iPhone Duo Could Become Apple’s Biggest Demand Driver, Analyst Predicts
Technology
iPhone Duo Could Become Apple’s Biggest Demand Driver, Analyst Predicts
September 12, 2026
3 Min Read
Pradum Shukla - Founder at Desh Crux
Technology
How AI Is Changing the Startup Journey for Young Entrepreneurs, and Where Pradum Shukla Fits In
September 12, 2026
7 Min Read
iPhone 18 Pro Max vs Galaxy S26 Ultra
Technology
iPhone 18 Pro Max vs Galaxy S26 Ultra: Six Key Differences to Know Before Buying
September 11, 2026
5 Min Read
iPhone 18 Pro, iPhone 18 Pro Max
Technology
iPhone 18 Pro, iPhone 18 Pro Max: Cheapest Countries to Buy These iPhones Compared With India
September 11, 2026
4 Min Read
The Blunt Times

The Blunt Times is a 24-hour news portal from Surat and south Gujarat. It was launched by senior journalist Melvyn Thomas, who has over 21 years of experience working with the top news organizations such as The Indian Express, The Times of India, and The Economic Times.

Popular
Ryan Group of Schools Hosts the 24th Indian Model United Nations in the Capital
September 15, 2026
Can Fin Homes Showcases ‘Project Tejas’, its Rs 296.95-Crore Enterprise Digital Transformation Programme
September 15, 2026
The Design Village, L’École de Design Nantes Atlantique Launch TNDV Dual Degree Programme Between India and France
September 15, 2026
Parul University Journalism Students Complete Six-Day Delhi Media Leadership Tour Across India’s Top Newsrooms
September 15, 2026
Categories
City Events
National
Business Vibes
Lifestyle
Business
Education
Spotlight
Entertainment
Regional
Health
Press Release
Sports

© 2026 All Rights Reserved, The Blunt Times

  • Terms of Service
  • Privacy Policy