Live
eineurope/
Home/Global/Topic · Malicious Docker images target KICS security tool
Global5d ago

Malicious Docker images target KICS security tool

Compromised Docker containers and VS Code extensions impersonating the KICS security scanner have been deployed in a supply chain attack targeting developer environments.

Sources
1 verified
Location
Updated
Thursday, 23 April 2026 at 07:42 UTC
No media · text-only dispatch
Synthesis · 1 sources
Malicious Docker containers and Visual Studio Code extensions impersonating Checkmarx's KICS infrastructure-as-code security scanner have been deployed in a supply chain attack. The compromised packages were designed to infiltrate developer environments through poisoned distribution channels, targeting organizations that rely on the popular open-source scanning tool. This incident highlights persistent vulnerabilities in developer toolchain distribution, particularly affecting cloud-native security workflows where containerized tooling and IDE extensions operate with elevated privileges across CI/CD pipelines.
e/eineurope · topic · T-05008