Sponsor of the Day:
Jerkmate
https://securityaffairs.com/191215/malware/checkmarx-supply-chain-attack-impacts-bitwarden-npm-distribution-path.html
Checkmarx supply chain attack impacts Bitwarden npm distribution path
Apr 25, 2026 - Bitwarden CLI hit by the Checkmarx supply chain attack. Version 2026.4.0 shipped malicious code in bw1.js via a compromised GitHub Action.
checkmarx supply chainattackimpactsbitwardennpm
https://thehackernews.com/2026/04/malicious-kics-docker-images-and-vs.html
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Malicious KICS Docker tags and VS Code versions 1.17.0, 1.19.0 enabled data exfiltration, risking exposed infrastructure secrets.
vs code extensionscheckmarx supply chaindocker imagesmaliciouskics
https://piefed.0x0c.link/c/selfhosted@lemmy.world/p/1497/bitwarden-cli-distributed-through-npm-has-been-compromised-bitwarden-statement-on-ch
Bitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply...
bitwarden clicheckmarx supplydistributednpmcompromised
https://it.slashdot.org/story/26/04/24/2032218/bitwarden-cli-is-the-next-compromise-in-checkmarx-supply-chain-campaign
Bitwarden CLI Is the Next Compromise In Checkmarx Supply Chain Campaign - Slashdot
Longtime Slashdot reader Himmy32 writes: Socket Security published an article on the compromise of the Bitwarden CLI client, which was pushed from Bitwarden's...
checkmarx supply chainbitwarden clinextcompromisecampaign
https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI 2026.4.0 was compromised via GitHub Actions in Checkmarx campaign, exposing secrets and distributing malicious npm code
checkmarx supply chainbitwarden clicompromisedongoingcampaign
https://securityboulevard.com/2026/04/bitwarden-cli-compromise-linked-to-ongoing-checkmarx-supply-chain-campaign/
Bitwarden CLI Compromise Linked to Ongoing Checkmarx Supply Chain Campaign - Security Boulevard
Apr 24, 2026 - While the attack on Bitwarden can be connected to the Checkmarx incident, it's unclear whether the same threat group is behind both.
checkmarx supply chainbitwarden clisecurity boulevardcompromiselinked
https://cambridgeanalytica.org/data-breaches-scandals/checkmarx-github-leak-dark-web-march-supply-chain-50845/
Checkmarx's own GitHub repository just leaked on the dark web after March 23 supply chain attack
Apr 28, 2026 - Security software maker Checkmarx confirms its own GitHub data was stolen and posted on the dark web following a March 23 supply chain attack.
supply chain attackgithub repositorydark webmarch 23checkmarx