logo

Checkmarx Alert: Malicious Plugins and GitHub Actions Hit OpenVSX in New Supply Chain Attack

ID: 3c72b627-c51e-5106-9e09-fa3637094be6

STIX ID: report--3c72b627-c51e-5106-9e09-fa3637094be6

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-03-24

Date Updated: 2026-04-23

Author: Ddos

...
...

Checkmarx reported a supply-chain incident on March 23, 2026 where attackers published compromised versions of two Checkmarx plugins (ast-results-2.53.0.vsix and cx-dev-assist-1.7.0.vsix) to the OpenVSX registry between 02:53–15:41 UTC, and briefly compromised the KICS GitHub Action distribution between 12:58–16:50 UTC; Checkmarx states the VS Code Marketplace and KICS itself were not affected, clean plugin versions have been released, and recommended mitigations include rotating secrets, auditing GitHub Actions logs for indicators (e.g., tpcp.tar.gz, aquasecurity, checkmarx.zone), and checking for shadow repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.