The Checkmarx KICS ecosystem was hit by a supply chain compromise that first affected the official GitHub Action and later appeared in official Docker Hub artifacts. Wiz reported that attackers repointed 35 KICS GitHub Action tags to malicious commits during a roughly four-hour window, delivering credential-stealing malware to users pinned to affected versions. The activity was linked with high confidence to TeamPCP, the actor previously tied to the Trivy GitHub Action compromise, based on shared tradecraft including the same RSA public key, similar naming conventions, and use of a compromised GitHub service account to redirect tags to attacker-controlled code. The malware used the domain checkmarx.zone, attempted token theft and exfiltration, and could create docs-tpcp repositories with stolen GITHUB_TOKEN credentials as a fallback channel.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-09, an unauthorized modified version of Checkmarx's AST Scanner Jenkins plugin was published to the Jenkins Marketplace, creating a supply-chain risk for Jenkins CI environments. Checkmarx warned customers not to trust versions published as of that date and advised verifying use of known-good version 2.0.13-829.vc72453fa_1c16.
On 2026-04-26, Checkmarx said a cybercriminal group had published company-related data on the dark web and that forensic evidence indicated the data came from a GitHub repository accessed through the initial March 23 supply-chain attack. The company said it locked down access to the affected repository, stated it was separate from the customer production environment, and continued investigating whether any customer information was involved.
On 2026-04-23, Checkmarx published an official security update confirming malicious artifacts had briefly appeared across multiple public distribution channels on April 22, including DockerHub KICS images, ast-github-action, the VS Code AST Results extension, and Developer Assist. The company said it removed the artifacts, rotated credentials, blocked attacker infrastructure, launched a third-party forensic investigation, and advised customers on safe versions, domains/IPs to block, and secret rotation if compromise was suspected.
On 2026-04-23, reporting on the Checkmarx Docker and extension supply-chain compromise linked the broader campaign to TeamPCP and said the actor appeared to claim responsibility on X. This extended TeamPCP attribution beyond the earlier March KICS GitHub Action incident to the April Docker and extension tampering activity.
On 2026-04-22, researchers linked the Bissa activity to Telegram handle @BonJoviGoesHard, display name "Dr. Tube," and bots including @bissapwned_bot and @bissa_scan_bot. The report said affected victims were notified, law enforcement was engaged, and the exposed server IP was withheld because of the sensitivity of the recovered data.
On 2026-04-22, The DFIR Report disclosed an exposed server tied to the Bissa scanner platform and a large-scale operation exploiting React2Shell (CVE-2025-55182). Recovered artifacts showed millions of scans, more than 900 confirmed compromises, tens of thousands of harvested .env files, and AI-assisted workflows used to troubleshoot and prioritize victims.
On 2026-04-22, Socket said evidence suggested the Checkmarx incident extended beyond Docker Hub to other distribution channels, including KICS-related VS Code extension versions 1.17.0 and 1.19.0 that could fetch and execute a remote addon from GitHub without integrity checks. Socket said it disclosed its findings to Checkmarx and that the investigation was ongoing.
By 2026-04-22, Socket reported a suspected supply-chain compromise in Checkmarx’s official checkmarx/kics Docker Hub repository after Docker detected malicious image activity. Attackers had reportedly overwritten legitimate tags such as v2.1.20 and alpine, added a fake v2.1.21 tag, and distributed a modified KICS binary capable of collecting and exfiltrating scan data.
On 2026-03-23, Wiz assessed with high confidence that TeamPCP was behind the KICS GitHub Action supply-chain attack, citing shared naming conventions and the same RSA public key seen in the earlier Trivy GitHub Action compromise. Wiz also documented new attacker tradecraft including the checkmarx.zone C2 domain, docs-tpcp repository exfiltration, and Kubernetes-focused persistence code.
Later on 2026-03-23, a user reported the KICS GitHub Action compromise and the repository was taken down at 16:50 UTC. It was subsequently reinstated after maintainers said the issue had been resolved.
On 2026-03-23, attackers using a compromised GitHub service account, cx-plugins-releases, repointed 35 Checkmarx KICS GitHub Action tags to malicious commits staged on a fork. The tampered action delivered credential-stealing malware to users pinned to affected version tags during an exposure window of roughly four hours.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcecheckmarx.com
Open sourcescworld.com
Open sourcecheckmarx.com
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourcethedfirreport.com
Open sourcewiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.