Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
ID: 875c66b0-8e26-5f80-a128-822b77595892
STIX ID: report--875c66b0-8e26-5f80-a128-822b77595892
Feed Name: The Hacker News
Threat Score
Security researchers reported that unknown actors compromised Checkmarx distribution channels by pushing poisoned Docker images to the official checkmarx/kics repository (modified KICS binary capable of collecting, encrypting, and exfiltrating scan reports) and by publishing VS Code extension releases that downloaded and executed remote code via the Bun runtime; organizations using affected images or extensions should treat any scanned secrets as potentially compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
