Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Checkmarx KICS Supply Chain Attack 2026: How Credentials…
Breach analysis Incident: 22 Apr 2026

Checkmarx KICS Supply Chain Attack 2026: How Credentials Stolen via Trivy Poisoned KICS Docker Images and VS Code Extensions

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
On this page

On 22 April 2026 attackers pushed malicious images to Checkmarx's official checkmarx/kics Docker Hub repository and published trojanised versions of two Checkmarx VS Code extensions and a Checkmarx GitHub Action. KICS is a free open source scanner for infrastructure-as-code files, which often contain credentials. The poisoned scanner and extensions stole GitHub tokens, cloud credentials, npm configuration, SSH keys and AI tool configuration files. This was the second wave against Checkmarx. Checkmarx says attackers first reached its GitHub repositories on 19 March 2026 through the Trivy supply chain attack and poisoned two of its GitHub Actions on 23 March. It says the April wave used cached credentials left from that access. TeamPCP claimed the attack on X. Checkmarx has since revoked classic GitHub tokens, moved publishing to OIDC and declared the incident contained. Its investigators found no access to its Checkmarx One SaaS platform or AWS production environment.

Key takeaways

  • On 22 April 2026 the official checkmarx/kics Docker Hub tags, ast-results and cx-dev-assist VS Code extensions and ast-github-action 2.3.35 were briefly replaced with credential-stealing versions, according to Checkmarx.
  • Checkmarx traces the attack to 19 March, when credentials stolen in the Trivy supply chain attack gave attackers access to its GitHub repositories. It says the April wave used cached credentials.
  • Socket says the poisoned extensions downloaded a hidden "MCP addon" that stole GitHub, cloud, npm and SSH credentials and used stolen GitHub tokens to plant workflows that dump CI secrets.
  • Checkmarx confirms the incident, including data from its GitHub repositories later published on the dark web. It says Mandiant found no access to Checkmarx One or its AWS production environment.
  • The identity lesson: if rotation after a supply chain breach misses cached or long-lived credentials, the attacker can come back weeks later through the same door.

At a glance

OrganisationsCheckmarx (KICS Docker images, VS Code and Open VSX extensions, GitHub Actions, Jenkins plugin) and developers and pipelines that pulled them
WhenAccess from 19 March 2026; first wave 23 March 2026; Docker image wave 22 April 2026; contained by 6 July 2026
AttackerTeamPCP claimed the attack on X; Socket found pattern-based overlaps but did not confirm attribution
Entry pointCredentials stolen through the Trivy compromise, including a publishing service account, then cached credentials reused in April
Identities abusedCheckmarx GitHub credentials and publishing accounts; then victims' GitHub tokens, cloud credentials, npm tokens, SSH keys and CI secrets
ImpactMalicious scanner images, extensions and Actions; Checkmarx repository data exfiltrated and published; CI secrets stolen from users
CategoryNHI. Incident class: confirmed NHI breach (stolen and cached publishing credentials used to ship credential-stealing tools)

What happened

The first wave came four days after the Trivy compromise. Checkmarx says its ast-github-action and kics-github-action carried malicious payloads between 12:58 and 16:50 UTC on 23 March 2026. Earlier the same day, its ast-results 2.53.0 and cx-dev-assist 1.7.0 extensions were poisoned on Open VSX. Sysdig, quoted by The Hacker News, said: "This suggests that the stolen credentials from the Trivy compromise were used to poison additional actions". Wiz said the Open VSX releases appear to have come through a compromised cx-plugins-releases service account. Checkmarx later said data was exfiltrated from its GitHub repositories on 30 March, and that a cybercriminal group published data on the dark web on 25 April that came from those repositories.

The second wave hit on 22 April. Docker alerted Socket to suspicious images in the official checkmarx/kics repository. Checkmarx lists the malicious Docker tags, including latest, alpine, debian and v2.1.20 and v2.1.21 variants, as live from 12:31 to 12:59 UTC. BleepingComputer reported a later window, which Checkmarx gives for ast-github-action 2.3.35. Socket found that the bundled KICS binary had been modified to produce an unredacted scan report, encrypt it and send it out. The VS Code extensions ast-results 2.63.0 and 2.66.0 and cx-dev-assist 1.17.0 and 1.19.0 downloaded a file called mcpAddon.js from a hardcoded GitHub URL and ran it with the Bun runtime. According to Socket, the code stole GitHub tokens, AWS, Azure and Google Cloud credentials, npm configuration, SSH keys, environment variables and Claude and MCP configuration files. It used stolen GitHub tokens to create a branch with a workflow that dumped CI secrets as artifacts, then deleted the branch and run.

TeamPCP posted on X: "Thank you OSS distribution for another very successful day at PCP inc." Socket told The Hacker News that "we cannot determine from artifacts alone whether this was retained access, re-compromise, or unremediated credentials". Checkmarx later stated that the second wave used cached credentials. Checkmarx told The Hacker News that "we have removed the malicious artifacts, revoked and rotated exposed credentials". GitGuardian described one victim environment where Dependabot pulled the trojanised checkmarx/kics:latest image on 22 April and ran it in CI with access to repository secrets. Bitwarden later linked a malicious npm release of its CLI, published the same evening, to the Checkmarx incident. A modified Checkmarx Jenkins plugin followed on 9 May. In its 6 July update Checkmarx said the incident was fully contained. Mandiant found that its AWS production environment was not affected and that there was no attacker access to Checkmarx One.

Timeline

DateEvent
19 March 2026Attackers gain access to Checkmarx's GitHub repositories through the Trivy supply chain attack, according to Checkmarx.
23 March 2026Malicious ast-github-action, kics-github-action and Open VSX extensions are published; Checkmarx identifies the access.
30 March 2026Data is exfiltrated from Checkmarx's GitHub repositories, according to Checkmarx.
22 April 2026Malicious KICS Docker images, VS Code extensions and ast-github-action 2.3.35 are published; TeamPCP claims the attack.
25 April 2026A cybercriminal group publishes data on the dark web that Checkmarx says came from its GitHub repositories.
9 May 2026A modified Checkmarx Jenkins AST plugin is published and removed the next day.
6 July 2026Checkmarx says the incident is fully contained.

How it happened: the identity attack path

  1. Credentials stolen upstream. The Trivy compromise harvested secrets from pipelines that ran it. Checkmarx says that gave attackers access to its GitHub environment on 19 March.
  2. Publishing identities abused. The attackers used that access, including a publishing service account according to Wiz, to push malicious Actions and extensions under Checkmarx's name.
  3. Cached credentials survived the clean-up. After the March response, credentials the attacker still held were used on 22 April to push malicious Docker images, extensions and an Action.
  4. A security tool turned collector. The trojanised scanner and extensions ran where secrets live, in developer workstations and CI jobs, and took GitHub, cloud, npm and SSH credentials.
  5. Stolen tokens used to spread. Stolen GitHub tokens let the malware plant secret-dumping workflows in victims' repositories, and the campaign reached other projects, including Bitwarden's npm package.

Impact

  • Confirmed: malicious Checkmarx Actions, extensions, Docker images and a Jenkins plugin across three waves; data exfiltrated from Checkmarx's GitHub repositories and later published on the dark web, according to Checkmarx.
  • Not affected: Checkmarx One SaaS and the AWS production environment, according to Mandiant's findings as reported by Checkmarx.
  • Downstream: credentials stolen from developers and pipelines that ran the poisoned tools. The number of affected users has not been published.
  • Wider: Bitwarden linked the malicious @bitwarden/cli 2026.4.0 npm release to the Checkmarx incident.

What this means for NHI governance

Checkmarx sells application security tools, and its scanners run inside the pipelines and IDEs that hold an organisation's most sensitive machine credentials. That makes the publishing identities behind those tools, such as GitHub tokens, service accounts and registry and marketplace credentials, part of every customer's attack surface. Once an attacker controls them, the scanner itself becomes the stealer.

The April wave shows why credential rotation after a breach must be complete and verified. Checkmarx says the attacker came back with cached credentials a month after the first wave. Its own fixes point to the right end state: no classic personal access tokens, no long-lived static credentials, and OIDC-based publishing that issues short-lived tokens to a specific workflow. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.

Recommendations

  • Pin images by digest and Actions by SHA. Do not run security tools from mutable tags such as latest. See our CI/CD Pipeline Identity Security Guide.
  • Rotate after any affected run. If you pulled the affected KICS images, extensions or Actions during the exposure windows, rotate GitHub, npm, cloud, SSH and CI/CD credentials. See our Leaked Credential Response Playbook.
  • Hunt for planted workflows and repositories. Look for unexpected branches, deleted workflow runs, files like format-check.yml and new public repositories in your GitHub organisation.
  • Retire classic tokens and long-lived publishing credentials. Follow Checkmarx's own remediation: move publishing to OIDC and remove static credentials. See our Secrets Management Guide.
  • Verify the rotation, not just the reissue. After an incident, confirm that every old token, cached credential and service account secret has stopped working. See our Service Account Security Guide.
  • Add a cooldown to automated updates. Configure Dependabot and Renovate to wait before adopting new image tags and releases.

Frequently asked questions

Which Checkmarx KICS artifacts were compromised?

On 22 April 2026, Checkmarx lists malicious checkmarx/kics Docker Hub tags (including latest, alpine, debian and v2.1.20 and v2.1.21 variants), ast-results 2.63 and 2.66 and cx-dev-assist 1.17 and 1.19 extensions, and ast-github-action 2.3.35. In March, kics-github-action, ast-github-action and two Open VSX extensions were affected.

Is the KICS attack linked to Trivy?

Yes. Checkmarx says attackers gained access to its GitHub repositories on 19 March 2026 through the Trivy supply chain attack, and that the April wave used cached credentials from that access.

Was Checkmarx One affected?

Checkmarx says Mandiant found no threat actor access to Checkmarx One and that its AWS production environment was not affected. Data from Checkmarx's GitHub repositories was exfiltrated and later published on the dark web.

Trivy supply chain attack 2026 · Bitwarden CLI npm compromise 2026 · LiteLLM PyPI Package Breach 2026 · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Security tools run with some of the broadest access in any pipeline. We help teams inventory the tokens and service accounts those tools use and publish with, replace long-lived credentials with short-lived ones, and rehearse a rotation that leaves nothing behind. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org