New Checkmarx supply-chain breach affects KICS analysis tool
ID: 3ad8d041-8329-5529-8fcb-a0f45e5e2941
STIX ID: report--3ad8d041-8329-5529-8fcb-a0f45e5e2941
Feed Name: Bleeping Computer
Hackers compromised Checkmarx KICS distribution channels — trojanizing Docker images and VS Code/Open VSX extensions — to install an 'MCP addon' that fetched mcpAddon.js, a multi-stage credential-stealing malware which encrypts and exfiltrates GitHub tokens, cloud credentials, SSH keys and other secrets to attacker-controlled infrastructure (notably audit.checkmarx.cx). Affected Docker tags were malicious between 2026-04-22 14:17:59 UTC and 15:41:31 UTC; the vendor removed malicious artifacts and advised rotating credentials, reverting to pinned SHAs/safe versions, and blocking listed domains/IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
