Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
2026-04-23T01:24:16Z•ecf7e28177e117e832b44860e75d42e4154ddc58d330bf9bbdbd699c21cce06f
BRIDGE:BREAK','lantronix','silex','serial-to-ip','mirai','botnetGoGraOTanthropic-mcpaspnet-corebackdoorcheckmarx-kicsdestructive-malwaredeveloper-tokensdocker-hubenergy-sectorggufknown-exploited-vulnerabilitiesmicrosoft-graph-apinpmprivilege-escalationrcesandbox-escapesglangsupply-chainterrariumtoken-theftvscode-extensionwiperworm
What happened
A broad set of high‑impact incidents and disclosures were reported: active supply‑chain compromises (malicious images/tags pushed to the official checkmarx/kics Docker Hub repo and malicious VS Code extensions; a self‑propagating npm supply‑chain worm dubbed CanisterSprawl that steals developer tokens), targeted malware campaigns (Harvester deploying a Linux GoGra backdoor using Microsoft Graph/Outlook as covert C2; Lotus Wiper destructive attacks against Venezuelan energy systems; Mustang Panda LOTUSLITE banking‑themed espionage), and infrastructure/IoT flaws (BRIDGE:BREAK in Lantronix/Silex,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ecf7e28177e117e832b44860e75d42e4154ddc58d330bf9bbdbd699c21cce06f
- Enrichment time
- 2026-04-23T01:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.