Switch language한국어
Back to the list

Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

TL;DR AI

Key summary

2 min read
  1. Checkmarx said data may have been taken from its GitHub repositories after access tied to a March 23, 2023 supply-chain attack.

  2. Socket said Bitwarden was also affected when a malicious npm package briefly moved through its CLI delivery path.

  3. The activity reused infrastructure linked to the Trivy campaign, showing how one vendor breach can cascade into others.

  4. The case highlights the risk of trusted software distribution channels being abused for credential theft and downstream compromise.

Read the original