Supply Chain Attack Compromises Checkmarx KICS Scanner and Bitwarden CLI Within Hours
On April 22, threat actors pushed malicious packages through
TeamPCP's coordinated intrusions against two security vendors within hours, with shared C2 infrastructure confirmed by Socket but not independently corroborated, mark a deliberate campaign using developer security tooling as a credential access pathway. The 97-minute Bitwarden CLI window understates actual exposure: any developer who installed the compromised package carries harvested credentials now outside Bitwarden's audit perimeter. The Lapsu$ dark web release of Checkmarx data dated one week after remediation indicates either deeper pre-remediation exfiltration than disclosed or operational coordination between Lapsu$ and TeamPCP. The C2 overlap may instead reflect false-flag staging to complicate attribution. Additional supply chain attacks against developer security tooling