MAL-2026-2232

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/vscode:open-vsx.org/checkmarx.cx-dev-assist/MAL-2026-2232.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2232
Published
2026-03-26T06:18:28Z
Modified
2026-03-26T06:47:02Z
Summary
Malicious code in checkmarx.cx-dev-assist (VSCode:https://open-vsx.org)
Details

-= Per source details. Do not edit below this line.=-

Source: google-open-source-security (b821135a3f6a7e85f6ed37a383363979118ad6c7b73433dd4882e99f24264155)

This extension is a compromised version of the offical Checkmarx VSCode extensions available on the Microsoft Marketplace, by the TeamPCP threat actor and related to the Trivy campaign.

The extension hunts for sensitive credentials and developer secrets for exfiltration. The extension also downloads a payload from an attacker controlled server. The malicious code will also try and maintain persistence using systemd.

Database specific
{
    "iocs": {
        "domains": [
            "checkmarx.zone"
        ]
    },
    "malicious-packages-origins": [
        {
            "import_time": "2026-03-26T06:18:48.137999Z",
            "modified_time": "2026-03-26T06:18:28Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        },
                        {
                            "fixed": "1.12.0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "b821135a3f6a7e85f6ed37a383363979118ad6c7b73433dd4882e99f24264155",
            "source": "google-open-source-security",
            "versions": [
                "1.10.0",
                "1.7.0",
                "1.6.0",
                "1.5.0",
                "1.4.0",
                "1.3.1772192178",
                "1.3.1772191535",
                "1.3.0",
                "1.2.0",
                "1.1.0"
            ]
        }
    ]
}
References

Affected packages

VSCode:https://open-vsx.org / checkmarx.cx-dev-assist

Package

Name
checkmarx.cx-dev-assist

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.12.0

Affected versions

1.*
1.1.0
1.2.0
1.3.0
1.3.1772191535
1.3.1772192178
1.4.0
1.5.0
1.6.0
1.7.0
1.10.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/vscode:open-vsx.org/checkmarx.cx-dev-assist/MAL-2026-2232.json"