logo

Supply chain attacks hit Checkmarx and Bitwarden developer tools

ID: 7b9c2c36-8563-58ba-abc5-819f80ecec7f

STIX ID: report--7b9c2c36-8563-58ba-abc5-819f80ecec7f

Feed Name: Sophos Blogs

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-30

...
...

Sophos reports that on April 22, 2026 attackers compromised distribution pipelines for two widely used developer tools—Checkmarx KICS and the Bitwarden CLI—by publishing trojanized releases (via Docker Hub, Open VSX, GitHub Actions, and npm). The malicious payloads harvested high-value secrets (GitHub/npm tokens, SSH keys, cloud credentials, AI assistant configs), encrypted them, and exfiltrated data to audit.checkmarx.cx (94.154.172.43); the Bitwarden package additionally weaponized stolen GitHub tokens to inject workflows and used victim repositories as dead drops. Sophos provides detections, IOCs, and remediation guidance including removal of malicious versions, credential rotation, audit of GitHub workflows/repos, and enabling MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.