Supply chain attacks hit Checkmarx and Bitwarden developer tools

2026-04-27T20:51:36Z111ef68cbbfeb170ce00681cb0fed6d7bc7c63b8850c75b9a0374c5dd20b3475
bitwardencheckmarxcommand-and-controldeveloper-toolspipelinesophos-x-opssupply-chainthreat-research

What happened

Sophos X-Ops reported two same-day supply-chain attacks that targeted developer tooling for Checkmarx and Bitwarden, both using the same command-and-control domain. The incidents indicate compromise of developer pipelines or tooling, creating risk of downstream code/artifact contamination and credential theft. Organizations should audit CI/CD pipelines and build environments, verify upstream dependencies and signing, and rotate credentials and secrets.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
111ef68cbbfeb170ce00681cb0fed6d7bc7c63b8850c75b9a0374c5dd20b3475
Enrichment time
2026-04-27T20:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.