Checkmarx Zero A.I CyberSecurity Scoring
Checkmarx Zero
Company Information
Website:https://checkmarx.com/zero/
Employees number:None
Number of followers:6,000
NAICS:541514
Industry Type:Computer and Network Security
Homepage:checkmarx.com
Checkmarx Zero Risk Score (AI oriented)
Between 700 and 749
Checkmarx ZeroComputer and Network Security
Updated:
30/04/2026
30/04/2026
717/1000
Moderate
Ba
Checkmarx Zero Global Score (TPRM)
xxxx
Checkmarx ZeroComputer and Network Security
Score locked

Checkmarx ZeroModerate
Current Score
717Ba (MODERATE)
01000
2 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
721
JULY 2026
720
JUNE 2026
719
MAY 2026
718
APRIL 2026
737
Cyber Attack
01 Apr 2026 • Checkmarx Zero
Checkmarx, Trivy and SAP: Official SAP npm packages compromised to steal credentials
SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack
716
CRITICAL-21
CHESAPSEC1777508710
SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack
Security researchers have uncovered a supply-chain attack targeting multiple official SAP npm packages, believed to be orchestrated by the TeamPCP threat group. The compromise affected four packages @cap-js/sqlite (v2.2.2), @cap-js/postgres (v2.2.2), @cap-js/db-service (v2.10.1), and mbt (v1.2.48) which support SAP’s Cloud Application Programming Model (CAP) and Cloud MTA, widely used in enterprise development.
The malicious packages contained a preinstall script that executed automatically upon installation, deploying a loader (setup.mjs) to fetch the Bun JavaScript runtime from GitHub. This runtime then ran an obfuscated execution.js payload, designed to steal sensitive credentials from developer systems and CI/CD environments, including:
- npm and GitHub authentication tokens
- SSH keys and developer credentials
- Cloud credentials (AWS, Azure, Google Cloud)
- Kubernetes configurations and secrets
- CI/CD pipeline secrets and environment variables
On CI runners, the malware used an embedded Python script to scan process memory (/proc/\<pid\>/maps and /proc/\<pid\>/mem) for secrets, bypassing log masking a tactic identical to previous TeamPCP attacks, such as those targeting Bitwarden and Checkmarx.
Stolen data was encrypted and exfiltrated to public GitHub repositories under victims’ accounts, marked with the description "A Mini Shai-Hulud has Appeared" a reference mirroring the "Shai-Hulud: The Third Coming" string from earlier attacks. The malware also employed GitHub commit searches as a dead-drop mechanism, decoding commit messages containing base64-encoded tokens to escalate access.
Additionally, the payload included self-propagation capabilities, using stolen credentials to modify other accessible packages and repositories, further spreading the infection.
Researchers have linked the attack to TeamPCP with medium confidence, citing similarities in code and tactics to prior incidents involving Trivy, Checkmarx, and Bitwarden. While the exact compromise vector remains unclear, evidence suggests an exposed NPM token from a misconfigured CircleCI job may have been exploited.
SAP has not yet responded to inquiries regarding the breach. The affected package versions have since been deprecated on npm.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
754
Cyber Attack
27 Mar 2026 • Checkmarx Zero
Telnyx: TeamPCP Uses Fake Ringtone File in Tainted Telnyx SDK to Steal Credentials
TeamPCP Exploits Telnyx Python SDK in Supply Chain Attack
737
MEDIUM-17
TEL1774873599
TeamPCP Exploits Telnyx Python SDK in Supply Chain Attack
A newly identified hacking group, TeamPCP, has targeted Telnyx, a widely used communication platform, by embedding malicious code in compromised versions of its Python SDK. The attack, uncovered by OX Security on 27 March 2026, follows a series of supply chain breaches linked to the group, including a recent compromise of the Trivy security tool on 19 March 2026.
The hackers uploaded two tainted versions of the Telnyx Python library (4.87.1 and 4.87.2) to PyPI, disguising malicious functionality within a file named _client.py. This file triggered the download of a seemingly innocuous ringtone.wav a decoy that, once executed, scanned infected systems for SSH keys, cryptocurrency wallets (Bitcoin, Ethereum), and cloud credentials (Google Cloud, Azure).
With the Telnyx SDK recording over 700,000 monthly downloads, the potential impact was significant. However, Telnyx confirmed that its core infrastructure including voice services, messaging, and AI inference remained unaffected, as the SDK operates independently of its backend systems. The breach was limited to developers who installed the compromised versions during the brief window they were live.
While no customer data was accessed, affected users were advised to downgrade to version 4.87.0 and rotate exposed credentials. The incident underscores the growing threat of supply chain attacks, where trusted software components are weaponized to distribute malware.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
754
JANUARY 2026
754
DECEMBER 2025
754
NOVEMBER 2025
754
OCTOBER 2025
754
SEPTEMBER 2025
754
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Checkmarx Zero ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in July 2026 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in June 2026 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in May 2026 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in April 2026 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in March 2026 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in February 2026 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in January 2026 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in December 2025 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in November 2025 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in October 2025 ??
What was Checkmarx Zero's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Checkmarx Zero's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Checkmarx Zero ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Checkmarx Zero's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?