MAL-2026-2231
Dashboard / Malicious Package / MAL-2026-2231
MAL-2026-2231
Summary: Malicious code in checkmarx.ast-results (VSCode:https://open-vsx.org)
Details: Source: google-open-source-security (3205937565e6fad63cbece12a8463cd52f3e95c10ac99ab7e62a317e9c18717a) This extension is a compromised version of the offical Checkmarx VSCode extensions available on the Microsoft Marketplace, by the TeamPCP threat actor and related to the Trivy campaign. The extension hunts for sensitive credentials and developer secrets for exfiltration. The extension also downloads a payload from an attacker controlled server. The malicious code will also try and maintain persistence using systemd.
References: https://checkmarx.com/blog/checkmarx-security-update/, https://www.wiz.io/blog/teampcp-attack-kics-github-action, https://www.reversinglabs.com/blog/teampcp-supply-chain-attack-spreads
Affected packages
Package
Name: checkmarx.ast-results
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
