WordPress Malware Alert: Checkmarx Supply-Chain Breach Impact

Date:

Malware Attack Targets Checkmarx KICS Tool, Compromising Developer Credentials

Hackers have infiltrated Docker images and VSCode extensions for the Checkmarx KICS analysis tool, which is designed to help developers secure their code. This breach allows the theft of sensitive information from developer environments, including cloud credentials and tokens.

The malicious attack was discovered by Socket after Docker alerted them to compromised images in the official Checkmarx repository. The hackers embedded a secret-stealing malware known as “MCP addon” that targets data processed by KICS. This malware encrypts sensitive information and sends it to a domain mimicking Checkmarx’s infrastructure.

Developers who used the affected tools between April 22 and April 22 should consider their data compromised and take immediate action to rotate credentials and rebuild their environments.

To protect against similar threats, users should avoid using unverified sources, regularly update software, and monitor for unusual activity.

Risk Level: High

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...