MAL-2026-2232

    Dashboard / Malicious Package / MAL-2026-2232

    MAL-2026-2232

    Published: 26 Mar 2026Last Modified: 26 Mar 2026

    Summary: Malicious code in checkmarx.cx-dev-assist (VSCode:https://open-vsx.org)

    Details: Source: google-open-source-security (b821135a3f6a7e85f6ed37a383363979118ad6c7b73433dd4882e99f24264155) This extension is a compromised version of the offical Checkmarx VSCode extensions available on the Microsoft Marketplace, by the TeamPCP threat actor and related to the Trivy campaign. The extension hunts for sensitive credentials and developer secrets for exfiltration. The extension also downloads a payload from an attacker controlled server. The malicious code will also try and maintain persistence using systemd.

    Affected packages

    Package

    Name: checkmarx.cx-dev-assist

    Purl:

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.10.0
    MAL-2026-2232 | CVE-DB