Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain - The Hacker News
Checkmarx's own security tools were weaponized. Malicious Docker images and VS Code extensions compromised a supply chain trusted by thousands of developers.

Why it matters
Supply chain attacks are moving upstream—compromising the security vendors themselves. This demonstrates that AI/security infrastructure is a high-value target and raises questions about trust models in developer tooling ecosystems.
The key facts
5 to knowMalicious KICS Docker images distributed via Checkmarx supply chain
VS Code extensions compromised as attack vector
Checkmarx (security vendor) was the target, not just a customer
Supply chain attack on security infrastructure—meta-risk for AI/DevSecOps workflows
Published April 22, 2026—recent incident
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain The Hacker NewsView Full Coverage on Google News