logo

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

ID: 875c66b0-8e26-5f80-a128-822b77595892

STIX ID: report--875c66b0-8e26-5f80-a128-822b77595892

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Security researchers reported that unknown actors compromised Checkmarx distribution channels by pushing poisoned Docker images to the official checkmarx/kics repository (modified KICS binary capable of collecting, encrypting, and exfiltrating scan reports) and by publishing VS Code extension releases that downloaded and executed remote code via the Bun runtime; organizations using affected images or extensions should treat any scanned secrets as potentially compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.