: This is the primary source for the incident that began on March 23, 2026 . It explains how malicious versions of official plugins— ast-results and cx-dev-assist —were published to the OpenVSX registry . Organizations that downloaded these specific versions during a small window in March were potentially impacted.
If you're looking to understand more about using Checkmarx for legitimate purposes or similar tools for assessing and improving the security of your software, here’s a guide on the general process and best practices: