Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2 infrastructure — Threadlinqs Intelligence
As of 2026-05-30, Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2 infrastructure is a high-severity supply chain threat attributed to TeamPCP (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0424 · Severity: HIGH · Status: MONITORING · Category: SUPPLY_CHAIN
Attribution: TeamPCP · N/A · FINANCIAL
Within a 5-hour window on 22 April 2026, threat actors trojanised the Checkmarx KICS scanner (Docker, Open VSX, GitHub Actions) and the @bitwarden/cli 2026.4.0 npm package. Both intrusions beacon to
On 22 April 2026, Sophos X-Ops, Socket, JFrog, and Aikido Security identified two coordinated supply-chain compromises hitting the trust chain that sits between developers and their CI/CD pipelines. The first wave targeted Checkmarx, where attackers pushed malicious artefacts to the company's Docker Hub repository (KICS tags v2.1.20, v2.1.20-debian, v2.1.21, debian, alpine, latest), to two Open VSX extensions (cx-dev-assist 1.17.0/1.19.0 and ast-results 2.63.0/2.66.0), and to the checkmarx/ast-github-action @ tag 2.3.35 used inside Bitwarden's CI/CD pipeline. The KICS Go binary was modified to add a telemetry routine that AES-256-GCM-encrypted SAST scan reports and exfiltrated them to https://audit.checkmarx[.]cx/v1/telemetry; the VS Code extensions deployed an approximately 10 MB obfuscated JavaScript payload (mcpAddon.js) executed under the Bun runtime, with backdated Git commits used to hide the malicious diffs.
Within hours, the same actor leveraged the compromised checkmarx/ast-github-action to inject malicious code into Bitwarden's release workflow, publishing a trojanised @bitwarden/cli@2026.4.0 to the public npm registry between 17:57 and 19:30 ET (a ~93-minute exposure window). The malicious package shipped a preinstall hook that invoked bw_setup.js, which downloaded the Bun runtime and decoded a second-stage 10 MB payload (bw1.js) via __decodeScrambled with seed 0x3039. bw1.js dropped a lockfile at /tmp/tmp.987654321.lock, staged data in /tmp/_tmp_<unix_epoch>/, packaged exfiltration archives as package-updated.tgz, and harvested GitHub PATs (memory-scraped from running gh/git processes), npm tokens from .npmrc, AWS credentials from ~/.aws/, Azure and GCP credentials, SSH keys, environment variables, shell history, AWS SSM/Secrets Manager and Azure Key Vault/GCP Secret Manager material, and configuration files for Claude, Cursor, Kiro, Codex CLI, Aider, and other MCP-enabled AI assistants. Persistence was established by appending loader stubs to ~/.bashrc and ~/.zshrc; an execution guardrail aborted on Russian system locales (LC_ALL, LC_MESSAGES, LANGUAGE, LANG). A worm component re-used stolen GitHub tokens to inject malicious workflows into accessible private repositories and to mirror exfiltrated data to attacker-controlled GitHub commits as a fallback channel.
Both payloads share the audit.checkmarx[.]cx/v1/telemetry endpoint resolving to 94.154.172.43, AES-256-GCM, the Bun runtime loader pattern, and Dune-themed naming conventions ({word}-{word}-{3digits}, e.g. atreides, fremen, harkonnen, melange, sandworm) embedded in the binary alongside the strings ''Shai-Hulud: The Third Coming'' and ''Butlerian Jihad'' manifesto references — tying the cluster to prior Shai-Hulud npm-worm activity. The Checkmarx intrusion was publicly claimed by TeamPCP through the @pcpcats account (since suspended); operational tradecraft differences between the two waves leave the Bitwarden leg attributed only to the Shai-Hulud cluster. Bitwarden remediated by yanking 2026.4.0, releasing 2026.4.1, and confirming no production or vault data was accessed; only ~334 users downloaded the malicious package. Sophos detections are JS/Steal-EAP, JS/Agent-BLZZ, and Linux/Agnt-HZ.
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494, CWE-1357
Target sectors: technology, software-development, financial, cryptocurrency, devsecops, managed-service-providers, enterprise
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1195, T1195.002, T1199, T1059.007, T1204.003, T1620, T1546.004, T1098.001, T1027, T1140