Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code
ID: 3b499b5f-66be-5721-b5de-20581757df06
STIX ID: report--3b499b5f-66be-5721-b5de-20581757df06
Feed Name: cybersecurityNews.com
A supply-chain attack tampered with Checkmarx KICS Docker images and weaponized VS Code/Open VSX extensions to deploy trojanized binaries and a ~10MB obfuscated JavaScript payload that steals GitHub, cloud, npm, SSH, and environment secrets, exfiltrating them to an attacker-controlled endpoint and enabling injection of malicious GitHub Actions and npm republishing for further propagation. Socket published technical analysis, IOCs (including C2, IP, and SHA256 hashes), and immediate remediation steps such as removing affected artifacts, rotating credentials, auditing repos, and pinning images to SHA256 digests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
