Checkmarx KICS and Bitwarden CLI Compromised in Fresh Supply Chain Attack (Campaign)
ID: 34a65a8f-c15d-5755-9bac-254d7a62343a
STIX ID: report--34a65a8f-c15d-5755-9bac-254d7a62343a
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-04-22
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Malicious versions of Checkmarx components (KICS Docker image, VS Code extension, and an ast-github-action) and a temporary malicious release of the @bitwarden/cli npm package were published to public repositories; the malicious artifacts harvest, encrypt, and exfiltrate secrets and the VS Code extensions can steal npm tokens to facilitate further supply-chain attacks. Docker images were removed quickly but some malicious extensions remained available on OpenVSX, and the activity is claimed by TeamPCP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
