MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Checkmarx supply-chain compromise publishes malicious developer artifacts across March-May

Checkmarx identified on 23 March 2026 a supply-chain incident originating from the Trivy compromise; attackers gained unauthorized GitHub access, published malicious Checkmarx actions and extensions and exfiltrated repository data. Continued access produced another wave of malicious artifacts on 22 April, and Checkmarx later assessed that access obtained in the March incident was used to publish a malicious Jenkins AST plugin on 9 May. Bitwarden separately linked a malicious CLI package to a compromised Checkmarx dependency.

84

Estimated severity

84 / 100

94

Source reliability

94 / 100

Approximate Date

23/03/2026

Targeted Company

CHECKMARX

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

BITWARDEN (Cybersecurity service provider)

Geographic Impact

Country Targeted Company

Israel

ISR

Other Affected Countries

No other affected countries reported

Target country

Israel

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impactDownstream customer disruption

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalwareUnauthorized accessData exfiltration

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.