Proprietary 2026-04-22 · 0 days ·Credential Theft

Checkmarx channels shipped stealers

Part of the Checkmarx vs TeamPCP campaign

A second Checkmarx wave hit DockerHub, GitHub Actions, VS Code Marketplace, and OpenVSX. The affected artifacts again put developer and CI credentials at risk.

Story

On April 22, Checkmarx found a second wave of malicious artifacts. This time the scope crossed more official channels: a public KICS DockerHub image, the AST GitHub Action, and both Microsoft Marketplace and OpenVSX releases of Checkmarx IDE extensions.

The Docker image window was short, less than thirty minutes. The extension windows were longer, ending first in the Microsoft marketplace and later in OpenVSX. Checkmarx said older known-safe versions were not overwritten, so the risk sat in new tags, mutable image tags, and auto-update paths that resolved during the exposure windows.

The recommended response matched the payload's job. Block TeamPCP lookalike infrastructure, pin immutable SHAs, review IDE auto-update behavior, and rotate secrets where affected artifacts ran. A scanner image, action, or IDE extension has proximity to source code, credentials, cloud metadata, and deployment material.

Checkmarx later linked the broader incident to credentials obtained after the March supply-chain compromise, reported March 30 repository data exfiltration, and said leaked material appeared on April 25. This record tracks the April artifact distribution wave, not the later disclosure event.

Affected Artifacts

checkmarx/kics

dockerhub · hub.docker.com · repository · Oci Image
Observed
2026-04-22
Fixed
Not listed
  • The mutable debian Docker tag was reported affected.
  • The mutable alpine Docker tag was reported affected.
  • A mutable latest tag or release channel was reported affected; it is recorded as scope rather than a fixed version identifier.
  • Checkmarx published truncated Docker image digests; they are intentionally not recorded as hashes because they are not complete SHA-256 values.

checkmarx.cx-dev-assist

vscode marketplace · repository · Extension
Observed
2026-04-22
Compromised Versions
  • 1.17
  • 1.19
Fixed
1.18.0, 1.20.0
  • The Microsoft Marketplace exposure ended at 2026-04-22 17:48:00 UTC.
  • The OpenVSX exposure ended at 2026-04-22 21:20:00 UTC.

Incident Context

Motive
Credential Theft
Attribution
Group
Cause
Compromised Account Credentials
Transitive
Yes
Actor
TeamPCP

Indicators

  • domaincheckmarx.cx
  • domainaudit.checkmarx.cx
  • domainupdates.checkmarx.cx
  • ip91.195.240.123
  • ip94.154.172.43
  • ip94.154.172.183
  • observableCheckmarx reported March 30 data exfiltration from GitHub repositories.
  • observableCheckmarx reported April 25 dark-web publication of data related to Checkmarx.

External References

Source record: proprietary/checkmarx-ast/meta.yaml