Proprietary ·

Checkmarx channels shipped stealers

A second Checkmarx wave hit DockerHub, GitHub Actions, VS Code Marketplace, and OpenVSX. The affected artifacts again put developer and CI credentials at risk.

Part of Checkmarx vs TeamPCP campaign

On April 22, Checkmarx found a second wave of malicious artifacts. This time the scope crossed more official channels: a public KICS DockerHub image, the AST GitHub Action, and both Microsoft Marketplace and OpenVSX releases of Checkmarx IDE extensions.

The Docker image window was short, less than thirty minutes. The extension windows were longer, ending first in the Microsoft marketplace and later in OpenVSX. Checkmarx said older known-safe versions were not overwritten, so the risk sat in new tags, mutable image tags, and auto-update paths that resolved during the exposure windows.

The recommended response matched the payload's job. Block TeamPCP lookalike infrastructure, pin immutable SHAs, review IDE auto-update behavior, and rotate secrets where affected artifacts ran. A scanner image, action, or IDE extension has proximity to source code, credentials, cloud metadata, and deployment material.

Checkmarx later linked the broader incident to credentials obtained after the March supply-chain compromise, reported March 30 repository data exfiltration, and said leaked material appeared on April 25. This record tracks the April artifact distribution wave, not the later disclosure event.

Appendix · Affected releases

checkmarx/ast-github-action github actions fixed 2.3.36
2.3.35 no sample yet
  • Package coordinates recorded for the affected releases: pkg:github/Checkmarx/[email protected].
  • The compromised commits are not retrievable from GitHub, checked 2026-09-03. All 83 forty-hex candidates in the archived references were tested against both actions; the malicious tags are gone and the closest fork holds the clean state.
checkmarx/kics docker hub
v2.1.20-debian no sample yet
v2.1.21-debian no sample yet
v2.1.21 no sample yet
v2.1.20 no sample yet
  • The mutable debian, alpine and latest Docker tags were reported affected, recorded as scope rather than fixed version identifiers. Coordinates: kics v2.1.20, v2.1.21, v2.1.20-debian and v2.1.21-debian.
  • Hashes are ordered as the alpine index, amd64 and arm64 images; the debian index, amd64 and arm64 images; then the latest index, amd64 and arm64 images.
  • Docker published these nine complete OCI index and platform-manifest digests. Checkmarx also listed six truncated values, which are not recorded because they are not complete SHA-256 digests.
  • None of the nine digests is retrievable, checked 2026-09-03: all 404 from Docker Hub and from mirror.gcr.io, which answers 200 for checkmarx/kics:latest, so the objects are gone rather than merely untagged.
checkmarx.ast-results vs code marketplace fixed 2.67.0
2.63 no sample yet
2.66 no sample yet
  • The Microsoft Marketplace exposure ended at 2026-04-22 17:48:00 UTC.
  • The OpenVSX exposure ended at 2026-04-22 21:20:00 UTC.
  • Package coordinates recorded for the affected releases: pkg:vscode/checkmarx/[email protected], pkg:vscode/checkmarx/[email protected].
checkmarx.cx-dev-assist vs code marketplace fixed 1.18.0, 1.20.0
1.17 no sample yet
1.19 no sample yet
  • The Microsoft Marketplace exposure ended at 2026-04-22 17:48:00 UTC.
  • The OpenVSX exposure ended at 2026-04-22 21:20:00 UTC.
  • Package coordinates recorded for the affected releases: pkg:vscode/checkmarx/[email protected], pkg:vscode/checkmarx/[email protected].
Payloads and stagesno published version

Indicators

  • domaincheckmarx.cx
  • domainaudit.checkmarx.cx
  • domainupdates.checkmarx.cx
  • ip91.195.240.123
  • ip94.154.172.43
  • ip94.154.172.183
  • observableCheckmarx reported March 30 data exfiltration from GitHub repositories.
  • observableCheckmarx reported April 25 dark-web publication of data related to Checkmarx.

References

  1. Update: Ongoing Checkmarx Supply Chain Security Incidentcheckmarx.com
  2. Update: Ongoing Checkmarx Supply Chain Security Incidentcheckmarx.com
  3. TeamPCP Targets Checkmarx KICS Docker Image in New Supply Chain Attackthehackernews.com
  4. TeamPCP Claims Responsibility for Checkmarx KICS Docker Hub Compromisesocket.dev
  5. TeamPCP Compromises Checkmarx KICS on Docker Hubgitguardian.com

Source record: proprietary/checkmarx-ast/meta.yaml