WorkThe story, in brief

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain - The Hacker News

Checkmarx's own security tools were weaponized. Malicious Docker images and VS Code extensions compromised a supply chain trusted by thousands of developers.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

Supply chain attacks are moving upstream—compromising the security vendors themselves. This demonstrates that AI/security infrastructure is a high-value target and raises questions about trust models in developer tooling ecosystems.

The key facts

5 to know
  1. Malicious KICS Docker images distributed via Checkmarx supply chain

  2. VS Code extensions compromised as attack vector

  3. Checkmarx (security vendor) was the target, not just a customer

  4. Supply chain attack on security infrastructure—meta-risk for AI/DevSecOps workflows

  5. Published April 22, 2026—recent incident

Go to the source

Reuters Technologynews.google.com

Publisher excerpt: Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain The Hacker NewsView Full Coverage on Google News
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work