DAPSSADAPSSA

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

By DAPSSA AI Desk | 2026-04-23T05:15:46.272Z
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Overview

Cybersecurity researchers have warned of malicious images pushed to the official "checkmarx/kics" Docker Hub repository. In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to an official release. The

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/04/malicious-kics-docker-images-and-vs.html

Join the Discussion