Checkmarx supply chain attack hit Docker images and extensions

Researchers at Socket and Docker have uncovered a supply chain attack on Checkmarx's KICS ecosystem, involving compromised Docker images and several Visual Studio Code extensions. The actor obtained credentials and pushed malicious images to Checkmarx's KICS repository on Docker Hub. Further investigation found signs that related Checkmarx developer tooling may also have been affected. Recent versions of the Visual Studio Code extensions gained the ability to download and execute remote add-ons without user confirmation. The attacks are connected through shared capabilities and infrastructure, and in both cases the purpose appears to be credential harvesting and further propagation through npm.

What this means for your organisation

KICS is used to scan infrastructure code for problems, which means it runs by design inside the build pipeline with access to what is being built. When a security tool becomes the attack vector, it lands in a place most controls are not watching. The likely consequence for a Norwegian organisation is stolen credentials from the build environment, and those credentials frequently open the cloud platform.

Berigo recommends

  • Check whether your pipelines pulled KICS images from Docker Hub during the affected period, and which versions were used.
  • Rotate every secret the build environment has had access to, without waiting for confirmation that you were hit.
  • Pin build dependencies to specific verified versions rather than moving tags such as latest.
  • Restrict what build jobs are allowed to reach on the network, so downloading of remote add-ons is blocked.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch