TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

The Hacker News

Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

[email protected] (The Hacker News) · 2026-04-27 · Read original ↗

ATT&CK techniques detected

3 predictions
T1195.001Compromise Software Dependencies and Development Tools
94%
“informer shared in an x post that the lapsus $ cybercrime group claimed three victims on its data leak site, one of which includes checkmarx. the data, per the listing, contains source code, employee database, api keys, and mongodb / mysql credentials. checkmarx suffered a breach…”
T1552.001Credentials In Files
67%
“informer shared in an x post that the lapsus $ cybercrime group claimed three victims on its data leak site, one of which includes checkmarx. the data, per the listing, contains source code, employee database, api keys, and mongodb / mysql credentials. checkmarx suffered a breach…”
T1213.003Code Repositories
36%
“checkmarx confirms github repository data posted on dark web after march 23 attack checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web. " ba…”

Summary

Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web. "Based on current evidence, we believe this data originated from Checkmarx's GitHub repository, and that access to that repository was facilitated through the initial supply chain attack of March 23, 2026,