LIVE NEWSROOM · --:-- · May 15, 2026
A LIBRARY FOR SECURITY RESEARCHERS

Checkmarx Confirms LAPSUS$ Supply Chain Attack: GitHub Data Stolen and Leaked

Post on X LinkedIn
Checkmarx Confirms LAPSUS$ Supply Chain Attack: GitHub Data Stolen and Leaked

Application security company Checkmarx has confirmed that the LAPSUS$ threat group published malicious code to its GitHub environment on March 23, 2026, exfiltrated data seven days later on March 30, and subsequently leaked it publicly. Organizations that integrate Checkmarx tools into CI/CD pipelines should treat any artifacts pulled from Checkmarx’s GitHub environment during the March 23–30 window as potentially compromised.

// 01 What We Know So Far

Checkmarx is a major application security vendor whose scanning tools are embedded in CI/CD pipelines at thousands of enterprises. LAPSUS$ — known for social engineering, SIM swapping, and insider recruitment — gained access to Checkmarx’s private GitHub repositories.

The attack timeline:
March 23, 2026: LAPSUS$ published malicious code to Checkmarx’s GitHub environment
March 30, 2026: The group exfiltrated data from the compromised repositories
Late April 2026: Stolen data was leaked publicly, forcing Checkmarx to confirm the breach

This is consistent with LAPSUS$’s documented playbook: compromise a high-trust vendor’s development infrastructure, plant malicious artifacts, and use the vendor as a supply chain conduit to downstream customers. Previous LAPSUS$ targets include Okta, Microsoft, Samsung, and Nvidia — all chosen for their privileged position in customer environments.

The specific data types exfiltrated have not been fully disclosed by Checkmarx. What makes this particularly significant for security teams is not the data theft itself, but the window during which malicious code existed in Checkmarx’s GitHub environment. Any tool version, scanner binary, or CI/CD integration pulled from that environment between March 23 and March 30 should be treated as potentially tampered until verified against official release checksums.

Checkmarx scanning tools run with elevated access inside build pipelines — the position that makes AppSec vendors such attractive supply chain targets.

// 02 What You Should Do Now

  1. Audit your CI/CD pipelines for any Checkmarx tool versions or artifacts downloaded between March 23 and March 30, 2026. Compare checksums against Checkmarx’s official releases distributed through their secure channels — not GitHub.

  2. Contact Checkmarx directly via their security advisory portal to request the full list of affected repositories and any IOCs associated with the malicious code introduced by LAPSUS$.

  3. Review GitHub Actions workflows and Dockerfiles that reference Checkmarx’s GitHub repositories or SHAs pointing to the March 23–30 window. Rebuild those pipeline stages from verified sources.

  4. Check pipeline execution logs from March 23–30 for anomalous outbound connections, unexpected process spawns, or privilege escalation events during scanner runs.

  5. Audit MFA enforcement and privileged developer access across all accounts with permissions to shared build infrastructure. LAPSUS$ primary vectors are social engineering and account takeover — internal access controls are the key defensive layer.


Sources: SecurityWeek, BleepingComputer

For any query contact us at contact@cipherssecurity.com

    TE
    Team Ciphers Security

    The Ciphers Security editorial team — practitioners covering daily threat intel, CVE deep-dives, and hands-on cybersecurity research. About us →

    Previous Google Patches CVSS 10 Gemini CLI RCE Flaw Threatening CI/CD Pipelines Next WordPress Quick Page/Post Redirect Plugin Hid Backdoor for Five Years, Affecting 70,000+ Sites

    Latest News

    YARA-X 1.16.0: Faster Scans, Panic Fixes, and Neovim LSP Support YARA-X 1.16.0 ships with performance improvements across 10 PRs, constant folding for bitwise ops, configurable mat… Instructure Removed from ShinyHunters' Leak Site as Canvas Breach Deadline Passes Instructure was quietly removed from ShinyHunters' extortion site after the May 12, 2026 deadline — no data dump, n… Costa Rica Joins Have I Been Pwned as the 42nd Government Costa Rica's CSIRT gains free access to Have I Been Pwned's government domain monitoring service, becoming the 42nd… LummaC2 Infostealer Targets US Critical Infrastructure: CISA-FBI Advisory AA25-141B and DOJ Domain Seizures CISA and FBI advisory AA25-141B details LummaC2 MaaS infostealer TTPs targeting critical infrastructure. DOJ seized… MacSync Stealer: Hackers Abuse Google Ads and Claude.ai Chats to Push Mac Malware Russian-speaking attackers combine Google Ads and Claude.ai shared chats in a ClickFix campaign deploying MacSync S… JDownloader Site Hacked, Installers Swapped with Python RAT Malware JDownloader's website was hacked May 6–7, 2026, replacing Windows and Linux installers with a Python-based RAT. Use… Operation HookedWing: 4-Year Phishing Campaign Hits 500+ Organizations Across Aviation, Energy, and Logistics Operation HookedWing has stolen credentials from 500+ organizations in aviation, energy, logistics, and critical in… Twelve Critical vm2 Node.js Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution A dozen CVEs in the vm2 Node.js sandbox library — including CVSS 10.0 flaws — allow sandbox escape and RCE. Update …
    Scroll to Top