Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions
Blog post from Socket
A significant security breach involving Docker Hub's Checkmarx/kics repository has been discovered, where attackers replaced existing and created new malicious image tags, including a false v2.1.21 tag, leading to the distribution of compromised KICS binaries. These altered binaries were embedded with unauthorized telemetry functions and exfiltration capabilities, posing severe risks to infrastructure-as-code files scanned using these images. The breach extended beyond Docker to other Checkmarx tools, such as VS Code extensions, which introduced malware capable of stealing and exfiltrating sensitive developer and cloud credentials. The attack leveraged Git history manipulation to stage malicious payloads, with evidence suggesting a broader supply chain compromise. TeamPCP is suspected of orchestrating the attack, which utilized stolen credentials to propagate malware across GitHub and npm ecosystems. Organizations using the affected Checkmarx artifacts are advised to treat this as a serious credential exposure incident, recommending immediate removal of compromised components, credential rotation, and thorough audits of GitHub and npm activities to mitigate further risks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 15 | 1,821 | 338 | 111 | +22% |
| MCP | 3 | 6,108 | 613 | 170 | +36% |
| Kubernetes | 1 | 2,306 | 381 | 103 | +25% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.