Checkmarx Supply-Chain Breach: Poisoned KICS Docker Images and Malicious VS Code Extensions

Security researchers warn of a Checkmarx supply-chain breach: attackers overwrote tags in the official checkmarx/kics Docker Hub (notably v2.1.20, alpine; adding v2.1.21) with a compromised KICS binary that exfiltrates data and can encrypt and send scan reports to an external endpoint; separately, Checkmarx VS Code extensions (cx-dev-assist and ast-results, versions 1.17.0/1.19.0) load a remote mcpAddon.js via a hard-coded GitHub URL, enabling credential theft and propagation as attackers injected a backdated commit to introduce a large payload; the attack uses stolen tokens to create public repos, GitHub Actions workflows, and to exfiltrate GitHub, AWS/Azure/GCP credentials, npm configs, SSH keys, and environment variables to public repos and to an endpoint controlled by the attackers; the operation also spreads through the npm ecosystem by republishing ~250 compromised packages; 51 repos reference Checkmarx Configuration Storage in READMEs; TeamPCP is suspected; mitigation includes removing affected artifacts, rotating credentials, auditing GitHub workflows, reviewing npm packages, and monitoring access logs.
- Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain The Hacker News
- Checkmarx suffers second massive supply chain attack, infecting developers with malware Cybernews
- Checkmarx KICS Docker Repo Hijacked in Malicious Code Injection Attack gbhackers.com
- Malicious Docker Images and VS Code Extensions Compromise Checkmarx Supply Chain CXO Digitalpulse
- Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code CyberSecurityNews
Reading Insights
0
24
4 min
vs 5 min read
84%
978 → 153 words
Want the full story? Read the original article
Read on The Hacker News