logo

Ongoing supply-chain attack 'explicitly targeting' security, dev tools

ID: a45cde4c-c54a-5582-88cf-1fa504911a70

STIX ID: report--a45cde4c-c54a-5582-88cf-1fa504911a70

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-04-27

Date Updated: 2026-05-06

...
...

### Executive summary Checkmarx has been impacted by a supply-chain attack linked to TeamPCP and Lapsus$, where credential-stealing malware introduced via compromised tools (Trivy, KICS, etc.) and poisoned artifacts resulted in stolen source code, API keys, database credentials, and employee data; the intrusion expanded to affect developer tooling including Bitwarden's CLI and GitHub repositories, creating a large blast radius and enabling follow-on extortion and potential ransomware campaigns while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.