Supply chain attacks hit Checkmarx and Bitwarden developer tools

2026-05-03T08:51:39Zaf96df5c22a662a96c8d6591a2dcf1a3d8c0bc198b29574175b77848030bbb46
AIBitwardenCVE-2026-31431CheckmarxCitrixBleed2GOLD ENCOUNTERLinuxMicrosoftMini Shai-HuludOpenClawPatch TuesdayPayoutsKingQEMUSAPSophos Firewallauthenticationfirewall-v22-mr1npmpasskeysproof-of-conceptransomwarered-teamsupply-chainvirtual-machine

What happened

Multiple Sophos posts (Apr–May 2026) report active and emergent threats and advisories: two same-day supply‑chain compromises targeting developer tools (Checkmarx and Bitwarden) sharing a command‑and‑control domain; a separate 'Mini Shai‑Hulud' supply‑chain campaign targeting SAP‑related npm packages; QEMU being abused to hide guest VMs to enable long‑term access, credential harvesting, data exfiltration and PayoutsKing ransomware delivery; a public proof‑of‑concept exploit for the Linux "Copy Fail" vulnerability (CVE-2026-31431); and Microsoft’s April Patch Tuesday addressing 163 CVEs. Also:-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
af96df5c22a662a96c8d6591a2dcf1a3d8c0bc198b29574175b77848030bbb46
Enrichment time
2026-05-03T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Supply chain attacks hit Checkmarx and Bitwarden developer tools · Baitaphish