MAL-2026-2232
Dashboard / Malicious Package / MAL-2026-2232
MAL-2026-2232
Summary: Malicious code in checkmarx.cx-dev-assist (VSCode:https://open-vsx.org)
Details: Source: google-open-source-security (b821135a3f6a7e85f6ed37a383363979118ad6c7b73433dd4882e99f24264155) This extension is a compromised version of the offical Checkmarx VSCode extensions available on the Microsoft Marketplace, by the TeamPCP threat actor and related to the Trivy campaign. The extension hunts for sensitive credentials and developer secrets for exfiltration. The extension also downloads a payload from an attacker controlled server. The malicious code will also try and maintain persistence using systemd.
References: https://checkmarx.com/blog/checkmarx-security-update/, https://www.wiz.io/blog/teampcp-attack-kics-github-action, https://www.reversinglabs.com/blog/teampcp-supply-chain-attack-spreads
Affected packages
Package
Name: checkmarx.cx-dev-assist
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
