Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
2026-04-28T01:24:11Z•816679d16e65d44c0d0ed23b92d9712cb18c4bbc963aad73158bb70d8f9094e7
active-exploitationaptbackdoorbitwardencisa-kevcve-2024-57726cve-2026-28950cve-2026-33626dark-webdata-exposuredockerfirestartergithubglasswormgopherwhisperkicslmdeploymalicious-packagesnpmphantomcoressrfsupply-chaintropic-trooperunc6692','vulnerabilities','patch','apple','ios','fake-apps','phvs-code-extensions
What happened
Multiple high-impact supply-chain and active-exploitation incidents reported by The Hacker News. Checkmarx confirmed data from its GitHub repository was posted to the dark web following a March 23 supply-chain attack; related supply-chain compromises include malicious KICS Docker images, trojanized VS Code extensions (GlassWorm cluster), and a compromised Bitwarden CLI package tied to the ongoing Checkmarx campaign. Researchers also reported rapid exploitation of LMDeploy SSRF (CVE-2026-33626) within hours of disclosure, CISA additions to its Known Exploited Vulnerabilities (including CVE-2024
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 816679d16e65d44c0d0ed23b92d9712cb18c4bbc963aad73158bb70d8f9094e7
- Enrichment time
- 2026-04-28T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.