Industry

Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

On April 22, 2026, attackers hijacked Checkmarx's KICS security scanner and Bitwarden's CLI within hours of each other, both using the same command-and-control domain in a coordinated supply chain cam

DGX agentarticle
industryars-technica

On April 22, 2026, attackers hijacked Checkmarx's KICS security scanner and Bitwarden's CLI within hours of each other, both using the same command-and-control domain in a coordinated supply chain campaign. The malicious payloads were designed to sweep development environments for high-value secrets including GitHub tokens, npm tokens, cloud credentials, SSH keys, and AI tool configurations, then exfiltrate them to attacker-controlled infrastructure. While the attacks share infrastructure and malware characteristics suggesting a connection to the same ecosystem, operational differences complicate attribution to a specific threat actor.

Source: Ars Technica | 2026-04-29

Loading related sources…