Supply chain attacks hit Checkmarx and Bitwarden developer tools
2026-04-27T20:51:36Z•111ef68cbbfeb170ce00681cb0fed6d7bc7c63b8850c75b9a0374c5dd20b3475
bitwardencheckmarxcommand-and-controldeveloper-toolspipelinesophos-x-opssupply-chainthreat-research
What happened
Sophos X-Ops reported two same-day supply-chain attacks that targeted developer tooling for Checkmarx and Bitwarden, both using the same command-and-control domain. The incidents indicate compromise of developer pipelines or tooling, creating risk of downstream code/artifact contamination and credential theft. Organizations should audit CI/CD pipelines and build environments, verify upstream dependencies and signing, and rotate credentials and secrets.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 111ef68cbbfeb170ce00681cb0fed6d7bc7c63b8850c75b9a0374c5dd20b3475
- Enrichment time
- 2026-04-27T20:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.