Checkmarx
Disclosed Apr 26, 20265 months agoConfirmed
Checkmarx confirms LAPSUS$ leak of GitHub data after Trivy-linked compromise
Application security firm Checkmarx said attackers used credentials from the Trivy supply-chain attack to access a private GitHub repository, pushed malicious KICS Docker images and extensions, and leaked about 96 GB via LAPSUS$. It said no customer data was stored there.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Apr 26, 2026 |
| Discovered | Mar 23, 2026 |
| Attack | Supply chain |
| Data exposed | Credentials and tokens, API keys, Source code |
| Sector | Tech · IL |
| Status | Confirmed |
| Part of | Trivy (2026) |
Sources
| Source | |
|---|---|
| Checkmarx security update April 26checkmarx.com · Official notice | Official notice |
| Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub datableepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Apr 26 |
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| Mar 315 months ago | Supply chain | Tech | Unverified | Unknown | |
| Mar 276 months ago | Supply chain | Government | Confirmed | Unknown | |
| Mar 246 months ago | Supply chain | AI | Unverified | Unknown | |
| Mar 216 months ago | Supply chain | Tech | Unverified | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.