Israel
ISR
Checkmarx identified on 23 March 2026 a supply-chain incident originating from the Trivy compromise; attackers gained unauthorized GitHub access, published malicious Checkmarx actions and extensions and exfiltrated repository data. Continued access produced another wave of malicious artifacts on 22 April, and Checkmarx later assessed that access obtained in the March incident was used to publish a malicious Jenkins AST plugin on 9 May. Bitwarden separately linked a malicious CLI package to a compromised Checkmarx dependency.
Estimated severity
84 / 100
Source reliability
94 / 100
Approximate Date
23/03/2026
Targeted Company
CHECKMARX
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
Israel
ISR
No other affected countries reported
Target country
Israel
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone