logo

New Checkmarx supply-chain breach affects KICS analysis tool

ID: 3ad8d041-8329-5529-8fcb-a0f45e5e2941

STIX ID: report--3ad8d041-8329-5529-8fcb-a0f45e5e2941

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Bill Toulas

...
...

Hackers compromised Checkmarx KICS distribution channels — trojanizing Docker images and VS Code/Open VSX extensions — to install an 'MCP addon' that fetched mcpAddon.js, a multi-stage credential-stealing malware which encrypts and exfiltrates GitHub tokens, cloud credentials, SSH keys and other secrets to attacker-controlled infrastructure (notably audit.checkmarx.cx). Affected Docker tags were malicious between 2026-04-22 14:17:59 UTC and 15:41:31 UTC; the vendor removed malicious artifacts and advised rotating credentials, reverting to pinned SHAs/safe versions, and blocking listed domains/IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.