Checkmarx Supply Chain Attack Leak Exposes GitHub Repository Data
Patch repository access controls, audit credentials, and notify stakeholders immediately.
Patch repository access controls, audit credentials, and notify stakeholders.
Summary
Checkmarx has confirmed that a supply chain attack on March 23 2026 compromised its GitHub repository, allowing a cybercriminal group to exfiltrate data.
The leaked data was subsequently posted on the dark web, exposing potentially sensitive information about Checkmarx’s codebase and internal processes. Investigators believe the initial breach was facilitated through a supply chain vector that granted the attackers access to the repository. Checkmarx is actively investigating the incident and has issued a public disclosure of the findings. The leak underscores the importance of securing third‑party code repositories and monitoring for unauthorized access. The incident also highlights the need for continuous supply chain risk management. Checkmarx has urged its partners to review repository permissions and audit credential usage. The organization is working with security vendors to mitigate any further exposure.
Key changes
- Checkmarx supply chain attack on March 23 2026 compromised its GitHub repository.
- Cybercriminal group published exfiltrated data on the dark web.
- Leaked data included sensitive codebase and internal process information.
- Initial breach facilitated through a supply chain vector granting repository access.
- Checkmarx disclosed ongoing investigation and public findings.
- Incident highlights need for securing third‑party code repositories.
- Partners urged to review repository permissions and audit credential usage.
- Checkmarx working with security vendors to mitigate further exposure.