Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Malicious KICS Docker image and VS Code extension impact Checkmarx supply chain

Self-propagating supply chain worm hijacks npm packages and steals developer tokens

Harvester uses Microsoft Graph API to bring Linux GoGra backdoor to South Asia

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Malicious KICS Docker image and VS Code extension impact Checkmarx supply chain
Identity

Malicious KICS Docker image and VS Code extension impact Checkmarx supply chain

By April 22, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 22, 2026Cloud security/software security

Cybersecurity researchers have warned about malicious images being pushed to the official “checkmarx/kics” Docker Hub repository.

Socket, a software supply chain security company, revealed in an alert published today that an unknown attacker was able to successfully overwrite existing tags, including v2.1.20 and alpine, while simultaneously introducing a new v2.1.21 tag that does not correspond to a public release. The Docker repository is archived at the time of writing.

“Analysis of the tainted images showed that the bundled KICS binaries had been modified to include data collection and extraction functionality that was not present in the canonical version,” Socket said.

“This malware can generate uncensored scan reports and send them encrypted to external endpoints, potentially posing a serious risk to teams using KICS to scan infrastructure files as code that may contain credentials and other sensitive configuration data.”

Further analysis of this incident revealed that related Checkmarx developer tools may also have been affected, including a recent Microsoft Visual Studio Code extension release that came with malicious code that downloaded and executed remote add-ons through the Bun runtime.

“This behavior occurred in versions 1.17.0 and 1.19.0 and was removed in 1.18.0. It relied on hard-coded GitHub URLs to retrieve and execute additional JavaScript without user verification or integrity validation,” Socket added.

Organizations that may have scanned their Terraform, CloudFormation, or Kubernetes configurations using affected KICS images should treat any secrets or credentials exposed in those scans as potentially compromised.

“Evidence suggests this is not an isolated Docker Hub incident, but rather part of a broader supply chain breach affecting multiple Checkmarx distribution channels,” the company noted.

Hacker News has reached out to Checkmarx for more information. I will update the article if I receive a response.

(This is a developing story. Check back for more details.)


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSelf-propagating supply chain worm hijacks npm packages and steals developer tokens

Related Posts

Self-propagating supply chain worm hijacks npm packages and steals developer tokens

April 22, 2026

Harvester uses Microsoft Graph API to bring Linux GoGra backdoor to South Asia

April 22, 2026

Lotus Wiper Malware Destroys Venezuelan Energy Systems

April 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Malicious KICS Docker image and VS Code extension impact Checkmarx supply chain

Self-propagating supply chain worm hijacks npm packages and steals developer tokens

Harvester uses Microsoft Graph API to bring Linux GoGra backdoor to South Asia

Cathie Wood’s ARK makes first lead investment in startup Lucra – It’s not AI

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.