HomeTechnologyWhy a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

TechnologyApril 29, 2026
1 min read
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
Security firms find themselves especially exposed.

It has been a bad six weeks for security firm Checkmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered malware to customers on two separate occasions. Now it has been hit by a ransomware attack from prolific fame-seeking hackers.

The streak of misfortunes started on March 19 with the supply-chain attack of Trivy, a widely used vulnerability scanner. The attackers behind the breach first breached the Trivy GitHub account and then used their access to push malware to Trivy users, one of which was Checkmarx. The pushed malware scoured infected machines for repository tokens, SSH keys, and other credentials.

Both a target and delivery mechanism

Four days later, Checkmarx’s GitHub account was compromised and began pushing malware to the security firm’s users. The company contained and remediated the breach and replaced the malware with the legitimate apps. Or so Checkmarx thought.

Read full article

Comments

Source: Ars Technica

Share this article

Related Articles

The Download: the North Pole’s future and humanoid data
2026Apr 30

The Download: the North Pole’s future and humanoid data

This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. Digging for clues about the North Pole’s past In t

Article5 min read
Read More
The logic of the racist Supreme Court isn’t adding up
2026Apr 30

The logic of the racist Supreme Court isn’t adding up

Close watchers of the Supreme Court knew that the conservative supermajority was about to murder what was left of the Voting Rights Act. Wednesday's decision in Louisiana v. Callais took down Section

Article1 min read
Read More
Congress keeps kicking surveillance reform down the road
2026Apr 30

Congress keeps kicking surveillance reform down the road

Congress has reauthorized Section 702 of the Foreign Intelligence Surveillance Act - but only for another 45 days. The extension is meant to give legislators more time to negotiate reforms to the cont

Article1 min read
Read More