Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
2,911
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

A significant security breach involving Docker Hub's Checkmarx/kics repository has been discovered, where attackers replaced existing and created new malicious image tags, including a false v2.1.21 tag, leading to the distribution of compromised KICS binaries. These altered binaries were embedded with unauthorized telemetry functions and exfiltration capabilities, posing severe risks to infrastructure-as-code files scanned using these images. The breach extended beyond Docker to other Checkmarx tools, such as VS Code extensions, which introduced malware capable of stealing and exfiltrating sensitive developer and cloud credentials. The attack leveraged Git history manipulation to stage malicious payloads, with evidence suggesting a broader supply chain compromise. TeamPCP is suspected of orchestrating the attack, which utilized stolen credentials to propagate malware across GitHub and npm ecosystems. Organizations using the affected Checkmarx artifacts are advised to treat this as a serious credential exposure incident, recommending immediate removal of compromised components, credential rotation, and thorough audits of GitHub and npm activities to mitigate further risks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 15 1,821 338 111 +22%
MCP 3 6,108 613 170 +36%
Kubernetes 1 2,306 381 103 +25%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.