Checkmarx experienced a cybersecurity supply chain incident beginning March 23, 2026, when attackers gained unauthorized access to GitHub repositories through a third-party supply chain attack. The breach resulted in malicious code being published to developer artifacts including VS Code extensions, GitHub Actions workflows, and a Jenkins plugin, with data subsequently appearing on the dark web in late April. This post provides ongoing security updates and remediation guidance for affected users.