# Security Vendor Source Code Exposure Class: Checkmarx and Trellix

- **Artifact ID:** CHQ-EX-2026-020
- **Public record:** https://record.cybersecurityhq.com/exhibits/chq-ex-2026-020
- **Machine-record SHA-256:** `f2c73e804c4a0ef20b39ab1cc2f59b6842433e3fb68a622c733d4c68c33c4b78`

## Complete structured record

```json
{
  "id": "CHQ-EX-2026-020",
  "title": "Security Vendor Source Code Exposure Class: Checkmarx and Trellix",
  "subtitle": "Two security vendors disclosed source code repository exposure within seven days through different actors and different access vectors, exposing the internal logic of security scanning and endpoint detection products to adversarial research and creating attacker knowledge that persists beyond patch cycles.",
  "classification_notice": [
    "This document is published as a CHQ Exhibit. It records historical conditions, breach events, and industry practices as they existed during the periods described. This Exhibit records observed conditions, exploitation mechanics, and structural patterns as documented in public disclosures, security research publications, and vendor advisories during the stated period.",
    "This document does not address present conditions and carries no current applicability. No evaluation of past practices is intended or implied.",
    "CHQ Exhibits are not superseded by later artifacts unless explicitly invalidated for factual error."
  ],
  "metadata": {
    "artifact_class": "EXHIBIT",
    "temporal_scope": "OPERATIONAL (APRIL 26 – MAY 2, 2026)",
    "authority_level": "NON-JUDGMENTAL",
    "reliance_status": "EXHIBIT_ONLY",
    "update_policy": "ERRATA_ONLY",
    "temporal_start": "2026-04-26",
    "temporal_end": "2026-05-02"
  },
  "sections": [
    {
      "heading": "I. Factual Record",
      "content": [
        "Checkmarx Source Code Publication: On April 25, 2026, the LAPSUS$ extortion group published approximately ninety-six gigabytes of Checkmarx source code on the dark web and via clearnet portals. Checkmarx confirmed the exfiltration on April 26, 2026.",
        "Checkmarx Initial Access: Forensic analysis traced the exfiltration to credential theft from the March 23, 2026 Trivy supply chain compromise (TeamPCP). Stolen credentials granted access to Checkmarx GitHub repositories. Initial repository access occurred on or about March 23. Confirmed exfiltration of source code completed on March 30. Publication occurred on April 25.",
        "Checkmarx Exposed Material: Source code of the Checkmarx KICS infrastructure-as-code scanner, source code of the Checkmarx AST application security testing platform, and source code of related Open VSX extensions. Checkmarx official statement confirmed that the exposure did not include customer data and stated that no evidence of source code exploitation or compromise of distribution processes had been found at the time of disclosure.",
        "Checkmarx Dwell Window: Initial access on March 23 to confirmed exfiltration completion on March 30 represented a seven-day operational window. The thirty-day window between exfiltration and publication suggests intentional staging by the LAPSUS$/TeamPCP coordination rather than rapid dissemination.",
        "Trellix Source Code Repository Breach: Trellix disclosed unauthorized access to a portion of its internal source code repository on May 2, 2026. Forensic investigation was launched with external experts. Law enforcement was notified.",
        "Trellix Attribution: No attribution was disclosed at the time of the public statement. The access vector was not disclosed.",
        "Trellix Affected Material: Trellix is the merger of McAfee Enterprise and FireEye and develops endpoint detection and response, network detection and response, and extended detection and response products. Source code of XDR and endpoint detection products was the affected category. Per Trellix’s official statement: “Based on our investigation to date, we have found no evidence that our source code release or distribution process was affected, or that our source code has been exploited.”"
      ]
    },
    {
      "heading": "II. Failure Pattern",
      "content": [
        "The two events are recorded as a paired exhibit because they demonstrate a target class rather than a single mechanism. Different actors, different access vectors, different vendor products. The shared property is that the targeted asset was the source code of products customers rely on as security controls.",
        "Source code exposure of security products operates differently from source code exposure of general software. A security product’s value derives from its detection logic — the rules, signatures, behavioral models, and correlation logic that determine what is flagged as suspicious and what is not. Possession of the source code grants an adversary detailed knowledge of what the product detects and what it does not detect.",
        "The asymmetry that follows is not remediated by patches. A patched product still implements the detection logic that the adversary now knows. The defender cannot rotate the knowledge an adversary has gained.",
        "The “no exploitation confirmed” claims at early-stage forensic investigation in both events follow a common epistemic pattern. At the time of public disclosure, forensic teams have established that access occurred and have not yet confirmed downstream exploitation. The absence of confirmation at this stage is not evidence that exploitation did not occur. The same stage preceded the confirmed Trivy cascade fallout in late March 2026.",
        "The temporal proximity is the third structural element. Two security vendor source code breaches in seven days, attributed to different actors with different access vectors, indicates the target class has been recognized by multiple operators independently.",
        "The boundary between this exhibit and adjacent exhibits matters. The Checkmarx exfiltration shares an initial access vector with the TeamPCP cascade documented in CHQ-EX-2026-014. The Trellix breach has no confirmed actor or vector. Pairing them in a single exhibit reflects the structural property they share — security vendor source code as target class — rather than asserting a coordinated campaign."
      ]
    },
    {
      "heading": "III. Referenced By",
      "content": [
        "CHQ-P-2026-011 — Position: Deployed Security Tool Presence Cannot Serve as Evidence of Functioning Control.",
        "CHQ-P-2026-012 — Position: Vendor Security Attestations Cannot Serve as Evidence of Operational Security State.",
        "CHQ-SC-2026-006 — Condition: Exploitation Timing Precedes Defender Awareness.",
        "CHQ-ED-2026-018 — Evidence Docket: CHQ-P-2026-015 (Execution Pipelines as Control Planes, successor docket).",
        "CHQ-ED-2026-019 — Evidence Docket: CHQ-P-2026-011 (Deployed Security Tool Presence, reinforcement docket)."
      ]
    }
  ],
  "closing_statement": "This Exhibit records historical conditions. It carries no present applicability. No judgment is made about any organization, vendor, security posture, or attribution conclusion.\n\nTemporal scope: April 26 – May 2, 2026. Exhibit issuance date is May 4, 2026. This Exhibit records findings as reported by named security research organizations, not as established fact.\n\nSources: Checkmarx official statement, BleepingComputer, LAPSUS$ Telegram channel observations, Trellix official statement, The Hacker News, Security Affairs, CyberSecurityNews.",
  "hash_scope": "Full exhibit content body",
  "hash_generated": "2026-05-04"
}
```
