CSIDB logo
Organisation

Checkmarx

Profile

Primary URL
checkmarx[.]com
Location
Israel
Sector
Technology
Known incidents
1 incident
Updated
2026-09-04 14:00
Aliases
1 alias

Organisation tracking is available to eligible accounts.

Profile narrative

Checkmarx is a cybersecurity organisation headquartered in Israel that develops software security products aimed at helping developers and enterprises identify and remediate vulnerabilities throughout the software development lifecycle. The company is known for its application security testing platform, which includes static application security testing (SAST), software composition analysis (SCA), and infrastructure-as-code scanning capabilities, with its KICS (Keeping Infrastructure as Code Secure) tool being one of its open-source offerings. Beyond its commercial platform, Checkmarx maintains a presence in the open-source community through projects such as KICS and various integrations with developer tooling ecosystems, including VS Code extensions and CI/CD platforms like GitHub Actions.

On 30 March 2026, Checkmarx confirmed a significant supply chain attack affecting its KICS open source project. The intrusion began with credential theft, which allowed attackers to hijack GitHub Action tags and subsequently poison multiple downstream artefacts, including OpenVSX plugins, GitHub workflows, a DockerHub image, VS Code and Developer Assist extensions, and the Bitwarden CLI NPM package. Once inside, the threat actors exfiltrated source code, employee data, API keys, and database credentials, portions of which were later published on a leak site. In response to the breach, Checkmarx removed the malicious packages, revoked compromised credentials, blocked attacker infrastructure, notified law enforcement, engaged Mandiant for incident response support, performed broad credential resets, tightened security controls, restricted repository access, and initiated a comprehensive code audit to contain the incident and prevent recurrence.

Based on the available source material, no specific information regarding Checkmarx's ownership structure, parent or subsidiary relationships, employee headcount, or customer base scale was provided, so these details cannot be stated with certainty. The organisation's sector positioning is, however, clearly situated within the application security and developer-focused cybersecurity tooling market, with particular specialisation in securing code and infrastructure configurations before deployment. Its role as both a commercial vendor and an open-source maintainer places it in a distinctive position where it serves enterprise customers while also contributing to broader community-driven security tooling efforts. The March 2026 incident highlights the particular risks facing organisations that maintain widely used open-source projects, as a single compromise can cascade into numerous downstream software supply chains, affecting both direct users and the wider developer ecosystem that relies on these tools.

Incidents

1 incident linked to this organisation.

CSIDB