Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

2026-04-27T19:24:12Zdccc296fb6c11e4ceccc5385b16ac80f018be48d68049401d0d0dc3f8e9d0515
APTCISA-KEVFIRESTARTERGlassWormLMDeployPhantomCoreSSRFTropic-TrooperUNC6692backdoorbitwardencheckmarxcredential-theftdockerexploit-in-the-wildmalwaremobile-fraudnpmphishingsupply-chainvs-code-extensions

What happened

A wave of active, high-impact incidents and supply-chain compromises was reported: Checkmarx confirmed data from its GitHub repository was posted to the dark web after a March 23 supply-chain attack, with related compromises impacting developer tooling (malicious KICS Docker images, VS Code extensions) and Bitwarden CLI (@bitwarden/cli@2026.4.0). Researchers also uncovered large-scale malicious extension/app campaigns (GlassWorm fake VS Code extensions, 26 fake wallet apps), a self-propagating npm supply-chain worm (CanisterSprawl) that steals developer tokens, and multiple targeted campaigns/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
dccc296fb6c11e4ceccc5385b16ac80f018be48d68049401d0d0dc3f8e9d0515
Enrichment time
2026-04-27T19:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.