Proprietary ·
Checkmarx channels shipped stealers
A second Checkmarx wave hit DockerHub, GitHub Actions, VS Code Marketplace, and OpenVSX. The affected artifacts again put developer and CI credentials at risk.
Part of Checkmarx vs TeamPCP campaign
On April 22, Checkmarx found a second wave of malicious artifacts. This time the scope crossed more official channels: a public KICS DockerHub image, the AST GitHub Action, and both Microsoft Marketplace and OpenVSX releases of Checkmarx IDE extensions.
The Docker image window was short, less than thirty minutes. The extension windows were longer, ending first in the Microsoft marketplace and later in OpenVSX. Checkmarx said older known-safe versions were not overwritten, so the risk sat in new tags, mutable image tags, and auto-update paths that resolved during the exposure windows.
The recommended response matched the payload's job. Block TeamPCP lookalike infrastructure, pin immutable SHAs, review IDE auto-update behavior, and rotate secrets where affected artifacts ran. A scanner image, action, or IDE extension has proximity to source code, credentials, cloud metadata, and deployment material.
Checkmarx later linked the broader incident to credentials obtained after the March supply-chain compromise, reported March 30 repository data exfiltration, and said leaked material appeared on April 25. This record tracks the April artifact distribution wave, not the later disclosure event.
Appendix · Affected releases
- Package coordinates recorded for the affected releases: pkg:github/Checkmarx/ast-github-action@2.3.35.
- The mutable debian Docker tag was reported affected.
- The mutable alpine Docker tag was reported affected.
- A mutable latest tag or release channel was reported affected; it is recorded as scope rather than a fixed version identifier.
- Hashes are ordered as the alpine/v2.1.20/v2.1.21 index, amd64 image, and arm64 image; the debian/v2.1.20-debian/v2.1.21-debian index, amd64 image, and arm64 image; then the latest index, amd64 image, and arm64 image.
- Docker published these nine complete OCI index and platform-manifest digests. Checkmarx also listed six additional truncated values, which are intentionally not recorded because they are not complete SHA-256 digests.
- Package coordinates recorded for the affected releases: pkg:docker/checkmarx/kics@v2.1.21, pkg:docker/checkmarx/kics@v2.1.20-debian, pkg:docker/checkmarx/kics@v2.1.21-debian, pkg:docker/checkmarx/kics@v2.1.20.
- The Microsoft Marketplace exposure ended at 2026-04-22 17:48:00 UTC.
- The OpenVSX exposure ended at 2026-04-22 21:20:00 UTC.
- Package coordinates recorded for the affected releases: pkg:vscode/checkmarx/ast-results@2.63, pkg:vscode/checkmarx/ast-results@2.66.
- The Microsoft Marketplace exposure ended at 2026-04-22 17:48:00 UTC.
- The OpenVSX exposure ended at 2026-04-22 21:20:00 UTC.
- Package coordinates recorded for the affected releases: pkg:vscode/checkmarx/cx-dev-assist@1.17, pkg:vscode/checkmarx/cx-dev-assist@1.19.
Indicators
- domaincheckmarx.cx
- domainaudit.checkmarx.cx
- domainupdates.checkmarx.cx
- ip91.195.240.123
- ip94.154.172.43
- ip94.154.172.183
- observableCheckmarx reported March 30 data exfiltration from GitHub repositories.
- observableCheckmarx reported April 25 dark-web publication of data related to Checkmarx.
References
- Update: Ongoing Checkmarx Supply Chain Security Incidentcheckmarx.com
- Update: Ongoing Checkmarx Supply Chain Security Incidentcheckmarx.com
- TeamPCP Targets Checkmarx KICS Docker Image in New Supply Chain Attackthehackernews.com
- TeamPCP Claims Responsibility for Checkmarx KICS Docker Hub Compromisesocket.dev
- TeamPCP Compromises Checkmarx KICS on Docker Hubgitguardian.com
Source record: proprietary/checkmarx-ast/meta.yaml