Checkmarx says LAPSUS$ leaked data from stolen GitHub repository

by

Checkmarx said the LAPSUS$ threat group leaked data taken from its private GitHub repository after a March 23 compromise that the company linked to a supply chain attack. The company said the leaked pack is 96GB.

KEY FACTS

  • Source The company linked the exposure to a security incident update.
  • Timeline The initial access took place on March 23, and more malicious artifacts were published on April 22.
  • Impact Checkmarx said the leaked material came from its GitHub repository and did not contain customer information.
  • Investigation A forensic review is still under way, and GitHub access was blocked during the review.

Checkmarx believes the entry point was a Trivy supply chain attack tied to TeamPCP, which exposed credentials from downstream users. The stolen credentials then gave the attacker access to Checkmarx GitHub repositories, according to the report.

After that access, the attacker published malicious code on March 23. On April 22, the same environment was used to publish malicious Docker images, VSCode extensions and Open VSX extensions for KICS, a security scanner from the company, and those files were used to steal credentials, keys, tokens and config files.

Checkmarx said the material that LAPSUS$ posted on its extortion portal belonged to the company and came from the March 23 compromise.

The company said it has not found customer data in the leaked files so far because that information is not stored in the GitHub repository. It said affected customers will be notified if any customer information is identified.

WHY IT MATTERS

The case shows how stolen credentials from one supply chain incident can lead to later access at another company. It also shows that data posted on extortion sites can be redistributed through public web portals, which can widen exposure while investigations are still ongoing.