Close Menu
    What's Hot

    The oil shortage is ending — and now comes the glut

    The State Of REITs: June 2026 Edition

    Bernardo Silva: Real Madrid sign Manchester City midfielder on free transfer as Jose Mourinho impact continues | Football News

    Facebook X (Twitter) Instagram
    Trending
    • The oil shortage is ending — and now comes the glut
    • The State Of REITs: June 2026 Edition
    • Bernardo Silva: Real Madrid sign Manchester City midfielder on free transfer as Jose Mourinho impact continues | Football News
    • Tottenham transfer news: Spurs’ Luka Vuskovic dilemma as two Brighton bids rejected after Jan Paul van Hecke deal agreed | Football News
    • West Antarctica Is Missing Way Too Much Ice
    • Quantum computing is growing—in Chicago!—and PsiQuantum keeps racking up wins
    • Trump Seeks to Delay Hearing for National Intelligence Pick to Pressure Congress on Elections Bill
    • Elon Musk, SpaceX, and the Rise of Space Capitalism
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

    adminBy adminApril 22, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 22, 2026Cloud Security / Software Security

    Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

    Cybersecurity researchers have warned of malicious images pushed to the official “checkmarx/kics” Docker Hub repository.

    In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to an official release. The Docker repository has been archived as of writing.

    “Analysis of the poisoned image indicates that the bundled KICS binary was modified to include data collection and exfiltration capabilities not present in the legitimate version,” Socket said.

    “The malware could generate an uncensored scan report, encrypt it, and send it to an external endpoint, creating a serious risk for teams using KICS to scan infrastructure-as-code files that may contain credentials or other sensitive configuration data.”

    Cybersecurity

    Further analysis of the incident has uncovered that related Checkmarx developer tooling may also have been affected, such as recent Microsoft Visual Studio Code extension releases that come with malicious code to download and run a remote addon through the Bun runtime.

    “The behavior appeared in versions 1.17.0 and 1.19.0, was removed in 1.18.0, and relied on a hardcoded GitHub URL to fetch and run additional JavaScript without user confirmation or integrity verification,” Socket added.

    Organizations that may have used the affected KICS image to scan Terraform, CloudFormation, or Kubernetes configurations should treat any secrets or credentials exposed to those scans as likely compromised.

    “The evidence suggests this is not an isolated Docker Hub incident, but part of a broader supply chain compromise affecting multiple Checkmarx distribution channels,” the company noted.

    The Hacker News has contacted Checkmarx for further information, and we will update the story if we hear back.

    (This is a developing story. Please check back for more details.)

    Chain Checkmarx Code Docker extensions hit images KICS malicious Supply
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticlePace of N.I.H. Funding Slows Further in Trump’s Second Year
    Next Article LG’s first RGB TV starts at $5,000 and is available to pre-order today
    admin
    • Website

    Related Posts

    Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

    June 17, 2026

    Ukraine Tries to Cut Off Crimea, Choking Russian Supply Routes

    June 17, 2026

    144 Mastra npm Packages Compromised via Hijacked Contributor Account

    June 17, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    The oil shortage is ending — and now comes the glut

    The State Of REITs: June 2026 Edition

    Bernardo Silva: Real Madrid sign Manchester City midfielder on free transfer as Jose Mourinho impact continues | Football News

    Tottenham transfer news: Spurs’ Luka Vuskovic dilemma as two Brighton bids rejected after Jan Paul van Hecke deal agreed | Football News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by