Checkmarx, a software security company, confirmed that credentials obtained through the Trivy attack enabled unauthorized access to its GitHub repositories and the publication of malicious artifacts. This highlights the downstream impact of the supply-chain campaign.