Build1 distinct publisher3 min readPublished
Mandiant's findings say the intrusion never reached Checkmarx One or production AWS, and that answers the vendor's question rather than the one a customer has about what a build box pulled in late March.
The Engineer · Build desk

science
TeamPCP hid its infostealer inside the scanners that audit everyone else's code1 distinct publisher
security
A poisoned Nx Console build rode VS Code's auto-update into GitHub's own repositories1 distinct publisher
security
Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 20201 distinct publisher
science
A backdoored litellm release turns every CI job that installed it into a credential incident1 distinct publisher
Compiled by The EngineerSomething wrong?How this is made
Four days passed between initial access and discovery [16]. Then thirty more days passed before the last evidence of threat actor activity, on April 22 [17][9]. Remediation ran for a month while the actor was still resident, which is unremarkable for an intrusion that included developer workstations [8], and that same month is when the release channels were being cleaned.
The advisory names three artifact classes for a reason [4]. A VS Code extension executes in the developer's editor session, with that developer's filesystem and frequently their tokens. An Actions workflow executes in CI with whatever the job's credentials can reach. A Jenkins plugin executes inside the controller. None of the three gets read per release by the team consuming it, which is why shipping through them is appealing.
The confirmations Checkmarx published on June 4 [15] share a subject. Production AWS, the Checkmarx One SaaS environment, the GitHub environment, the workstations [7][8]. Every one of them is a statement about Checkmarx's estate. The question a customer actually has is which build of which extension landed on which machine, and in which week.
The company says it removed the malicious artifacts, published clean verified replacements across all affected channels [10], and blocked outbound access to attacker-controlled infrastructure [11]. Both are correct vendor-side moves, and neither of them tells you whether one of your laptops pulled a poisoned build. To scope that, you need artifact names, version ranges and hashes, plus the destinations that were blocked. In the summary as published, the heading marked Timeline is followed by no dated entries, and none of those indicators appear anywhere in the document [19].
The hardening list reads like people who took the finding seriously: CI/CD pipeline security tooling, access management controls, credential rotation, and increased monitoring and detection [13]. Access to the affected repositories was locked down and law enforcement was engaged [12]. There is also a code audit to verify no further malicious code is present beyond what was already found [14], an unusual admission for a company to make about its own repositories. The document is less settled about its own status than the headline suggests: one section describes the company as being in the final stages of the investigation, another declares it complete [20]. The completion note is dated July 6, seventy-five days after the last observed activity [18].
Two hops matter here. Someone else's compromise supplied the initial access [3]. Checkmarx's own distribution channels supplied the next one [4]. A cybercriminal group then published repository data to the dark web [5], which is a third consequence with its own timeline. If you consume build-time artifacts from a security vendor, your dependency graph contains that vendor's dependency graph, and its detection latency becomes yours too.
Ranked by verification strength, evidence, and original report placement.
Mandiant confirmed that the AWS production environment was not impacted and that there was no threat actor access to the Checkmarx One SaaS environment.
Mandiant confirmed that threat actor activity was limited to the Checkmarx GitHub environment, a limited number of infected workstations, and initial reconnaissance of Checkmarx AWS credentials.
Checkmarx states that the Mandiant confirmations were previously reported as of June 4, 2026.
Checkmarx published a supply chain security incident summary, updated July 6, 2026, covering an incident affecting certain developer artifacts distributed through third-party channels.
On March 23, 2026, Checkmarx identified that attackers had gained unauthorized access to Checkmarx's GitHub repositories.
The unauthorized access occurred on March 19, 2026 due to the Trivy Supply Chain Attack, according to Checkmarx.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One interested account, no checkable detail
Everything substantive here — the Trivy entry point, the poisoned extensions, the containment finding — is Checkmarx describing its own breach. Mandiant is invoked on every important point and quoted on none. And the document carrying it publishes a Timeline heading with nothing beneath it and not one version number or hash, so a reader who consumed those artifacts in March has no way to test a single sentence of it.
Channels confirmed, blast radius unmeasured
The concrete part is that real code moved: malicious artifacts went out through VS Code, GitHub Actions and Jenkins distribution, and clean replacements went back across the same routes. The unknown part is everything a responder would scope on — which versions, how many installs, over what window. Two dated milestones and no numbers behind them.
Perimeter answers to customer questions
Both headline reassurances are scoped to Checkmarx's own perimeter — production AWS untouched, Checkmarx One untouched — and neither speaks to what a customer's build box pulled down on March 20. Stack that against a page that calls the investigation complete in one paragraph and in its final stages in another, and a code audit still described as underway, and the closure on offer runs well ahead of what is shown.
The breached vendor is the only witness
Checkmarx sells supply chain security and was compromised through a supply chain attack on another security tool; the account of that compromise is published on Checkmarx's own blog, and the forensic authority cited is a firm Checkmarx retained and paid. The page's closing lines thank customers for their patience and promise to maintain their trust. That is the register of the whole document, and it is not a disinterested one.
Sure of the wording, unsure of the substance
What Checkmarx said, and when, is not in doubt — this is a primary document and its self-contradiction is visible on the page. Whether the containment holds is a different question, and no one outside Checkmarx and its retained responder has looked at it. So: high confidence in the reading, moderate at best in the reality being described.