Checkmarx KICS Docker Repo Compromised
In a significant supply chain breach, the official Checkmarx KICS Docker repo was compromised, injecting malicious code. On April 22, 2026, Docker’s monitoring detected suspicious activities with KICS image tags, alerting Socket researchers to investigate. Attackers altered existing tags like v2.1.20 and introduced a dubious v2.1.21 tag without upstream legitimacy. The breach impacted widely used tags, affecting development infrastructure security.
The malicious code, embedded in the KICS images, targeted Infrastructure as Code by exfiltrating sensitive data to a hostile endpoint. This threat became more evident as researchers discovered related attacks on VS Code and Open VSX extensions. A JavaScript payload, mcpAddon.js, further facilitated multi-layered credential theft and repository manipulation.
Checkmarx users should remove compromised images and extensions, rotate credentials, and audit systems for intrusions. Security teams are urged to pin Docker images to verified SHA256 digests. For in-depth coverage and further details, read the full article here:
Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code
