IC Technology & Surveillance — 2026-05-04

Supply Chain Attack Compromises Checkmarx KICS Scanner and Bitwarden CLI Within Hours

On April 22, threat actors pushed malicious packages through Checkmarx's GitHub and Docker Hub repositories, then injected a credential-stealing payload into Bitwarden CLI version 2026.4.0 via npm for a 97-minute window between 5:57 and 7:30 PM ET, as Socket and Bitwarden both reported. Socket attributed both intrusions to the same actor, identified as TeamPCP, based on shared C2 endpoints and infrastructure. Bitwarden confirmed no vault data was accessed; only users who installed the package via npm in that window were affected. Checkmarx separately disclosed that the Lapsu$ ransomware group dumped private company data on the dark web from material dated March 30, after the company's March 23 remediation, per Ars Technica.

Analysis
TeamPCP's coordinated intrusions against two security vendors within hours, with shared C2 infrastructure confirmed by Socket but not independently corroborated, mark a deliberate campaign using developer security tooling as a credential access pathway. The 97-minute Bitwarden CLI window understates actual exposure: any developer who installed the compromised package carries harvested credentials now outside Bitwarden's audit perimeter. The Lapsu$ dark web release of Checkmarx data dated one week after remediation indicates either deeper pre-remediation exfiltration than disclosed or operational coordination between Lapsu$ and TeamPCP. The C2 overlap may instead reflect false-flag staging to complicate attribution. Additional supply chain attacks against developer security tooling almost certainly will surface before July 2026.
1 sources
  1. Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica

View in full brief →

UNCLASSIFIED // OPEN SOURCE