Supply Chain Attack at Application Security Testing Platform Provider Checkmarx

July 2, 2026

INCIDENT

Application security testing (AppSec) platform provider Checkmarx experienced a cybersecurity supply chain incident in March affecting certain developer artifacts distributed through third-party channels and it is continuing supplying updates to the incident.
Checkmarx is an enterprise-grade AppSec platform designed to help developers and security teams identify and remediate vulnerabilities in their code. It seamlessly integrates into developer workflows and CI/CD pipelines to secure software from early coding stages through to production.
The attack all unfolded on March 23 when Checkmarx discovered attackers gained unauthorized access to its GitHub repositories. This access occurred on March 19 due to the Trivy Supply Chain Attack.

Incident Date

March 19, 2026

Estimated Cost

Unknown at this time

Victims

Type of Malware

No Malware identified

Threat Source

No threat source identified