Featured
Navsari mango crop damage, the blunt times
Gujarat : Navsari’s Famous Kesar and Hafus Mangoes Hit Hard as Weather Wrecks Harvest
Subhajit Dhar Brings AI-Powered Growth Systems to B2B and D2C Brands Across India
Tiny Bubbles Child Development Centre Completes 500+ Therapy Sessions Within Six Months of Launch in Pune
May 16, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Search the Site
Popular Searches:
Chatgpt Nasa Halloween
Recent Posts
Paimaish Interiors Hits 100-Project Milestone, Setting a New Standard for ‘Quiet Luxury’ in Delhi NCR
May 16, 2026
Kimberley Process Mumbai 2026, the blunt times
India Reinforces Trust in Natural Diamonds as Kimberley Process Meet Concludes in Mumbai
May 15, 2026
F Gear and Uber Fashion Merchandise Pvt. Ltd. Build a Legacy Rooted in Function, Form and Reliability
May 15, 2026
The Blunt Times The Blunt Times
  • National
  • City Events
  • Business Vibes
  • Education
  • Entertainment
  • Regional
    • Bharuch
    • Dang
    • Navsari
    • Surat
    • Valsad
    • Hindi
    • Gujarati
  • Health
  • Crime corner
  • Sports
  • Spotlight
Follow us
Home/Technology/Checkmarx hit again, popular tools spreading credential-stealing malware
Technology

Checkmarx hit again, popular tools spreading credential-stealing malware

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular...

Santhosh Kumar
April 25, 2026 2 Min Read

Checkmarx has reportedly suffered a second security incident within a month, with attackers injecting credential-stealing malware into widely used developer tools. The compromise has affected popular distribution channels including Docker Hub and VS Code extensions, raising serious concerns about software supply chain security and developer trust in open-source ecosystems.

Table Of Content

  • Malware found in widely used developer tools
  • Credential theft and data exfiltration risks
  • Supply chain impact and developer exposure
  • Ongoing supply chain attack campaign

Malware found in widely used developer tools

Security researchers revealed that malicious code was inserted into Checkmarx’s KICS (Keeping Infrastructure as Code Secure) Docker images and VS Code extensions. The infected versions were uploaded using existing trusted tags such as v2.1.20 and latest, meaning developers unknowingly downloaded compromised builds instead of safe ones. Since KICS is downloaded millions of times for infrastructure security scanning, the impact could potentially be widespread across development environments.

Credential theft and data exfiltration risks

The injected malware is designed to steal sensitive developer and cloud credentials, including GitHub tokens, AWS and Azure credentials, Google Cloud access data, SSH keys, and environment variables. It then encrypts and exfiltrates the stolen information to attacker-controlled systems. In some cases, it even pushes stolen data into public repositories under victim accounts, increasing the risk of further exploitation and secondary attacks.

Supply chain impact and developer exposure

Checkmarx tools are widely used in CI/CD pipelines to scan infrastructure-as-code files like Terraform, Kubernetes, and CloudFormation. Security experts warn that any secrets exposed during scans should now be considered compromised. Developers are being urged to rotate credentials, audit GitHub repositories, review npm packages, and check cloud logs for unusual activity as part of incident response measures.

Ongoing supply chain attack campaign

Security analysts suggest the attack may be linked to a threat group known as TeamPCP, which has been targeting software supply chains across ecosystems like GitHub, npm, PyPI, Docker Hub, and OpenVSX since late 2025. This campaign has previously affected other major developer tools, highlighting a growing trend of attackers focusing on trusted open-source infrastructure to spread malware at scale.

Tags:

CheckmarxCredential TheftDocker HubMalwareSupply Chain Attack

Share Article

AAP ticket for cash Surat, the blunt times
Previous Post

Ticket-for-Cash Row Rocks AAP in Surat Before Civic Polls

Shrimad Rajchandra hospital Physiological cord clamping research India, the blunt times
Next Post

Shrimad Rajchandra hospital’s Cord Clamping Research Gets Global Recognition

Picked
Navsari mango crop damage, the blunt times
Gujarat : Navsari’s Famous Kesar and Hafus Mangoes Hit Hard as Weather Wrecks Harvest
Navsari mango crop damage, the blunt times
Gujarat : Navsari’s Famous Kesar and Hafus Mangoes Hit Hard as Weather Wrecks Harvest
Subhajit Dhar Brings AI-Powered Growth Systems to B2B and D2C Brands Across India
Tiny Bubbles Child Development Centre Completes 500+ Therapy Sessions Within Six Months of Launch in Pune
Enjen AI Wants to Replace 18-Month ERP Rollouts With AI Systems That Go Live in Weeks
Dr Nikhil Kanase Suman Rehab Center and Shanti Wellness and Rehab Pune Are Confronting the Reality Most Mental Health Systems Avoid
Popular Posts
Enjen AI Wants to Replace 18-Month ERP Rollouts With AI Systems That Go Live in Weeks
By TBT NEWS SERVICE
Dr Nikhil Kanase Suman Rehab Center and Shanti Wellness and Rehab Pune Are Confronting the Reality Most Mental Health Systems Avoid
By TBT NEWS SERVICE
Nikhil Khare: The Civil Servant Who Never Stopped Writing the Darkness Within
By TBT NEWS SERVICE
Actor Sharad Singh will be seen playing a powerful police officer in "The Narmada Story"-TBT
Actor Sharad Singh will be seen playing a powerful police officer in “The Narmada Story”
By TBT Online Desk
Sonnal Singh-PNn
From Indore Dreams to Mumbai Spotlight: Sonnal Singh’s Inspiring Journey to Stardom
By TBT Online Desk
Gujarat fuel saving measures, the blunt times
Gujarat Govt Launches Fuel-Saving Drive, Orders Virtual Meetings and Adds 300 New ST Buses
By Times News Network

Read Next

Technology
Subhajit Dhar Brings AI-Powered Growth Systems to B2B and D2C Brands Across India
May 15, 2026
2 Min Read
Identityy
Technology
How Identityy A Treefe Technology Company Limited Is Transforming Online Identity, Privacy, and Creator Engagement in India
May 15, 2026
3 Min Read
Technology
Google Android Show 2026: Gemini AI, GoogleBook, Android 17 and Everything Announced
May 13, 2026
5 Min Read
Technology
5 Best Mobile Brands in 2026
May 13, 2026
5 Min Read
The Blunt Times

The Blunt Times is a 24-hour news portal from Surat and south Gujarat. It was launched by senior journalist Melvyn Thomas, who has over 21 years of experience working with the top news organizations such as The Indian Express, The Times of India, and The Economic Times.

Popular
Gujarat : Navsari’s Famous Kesar and Hafus Mangoes Hit Hard as Weather Wrecks Harvest
May 15, 2026
Gujarat : Navsari’s Famous Kesar and Hafus Mangoes Hit Hard as Weather Wrecks Harvest
May 15, 2026
Subhajit Dhar Brings AI-Powered Growth Systems to B2B and D2C Brands Across India
May 15, 2026
Tiny Bubbles Child Development Centre Completes 500+ Therapy Sessions Within Six Months of Launch in Pune
May 15, 2026
Categories
City Events
National
Business Vibes
Lifestyle
Spotlight
Regional
Education
Entertainment
Health
Press Release
Trending
Sports

© 2026 All Rights Reserved, The Blunt Times

  • Terms of Service
  • Privacy Policy