Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

2026-04-23T01:24:16Zecf7e28177e117e832b44860e75d42e4154ddc58d330bf9bbdbd699c21cce06f
BRIDGE:BREAK','lantronix','silex','serial-to-ip','mirai','botnetGoGraOTanthropic-mcpaspnet-corebackdoorcheckmarx-kicsdestructive-malwaredeveloper-tokensdocker-hubenergy-sectorggufknown-exploited-vulnerabilitiesmicrosoft-graph-apinpmprivilege-escalationrcesandbox-escapesglangsupply-chainterrariumtoken-theftvscode-extensionwiperworm

What happened

A broad set of high‑impact incidents and disclosures were reported: active supply‑chain compromises (malicious images/tags pushed to the official checkmarx/kics Docker Hub repo and malicious VS Code extensions; a self‑propagating npm supply‑chain worm dubbed CanisterSprawl that steals developer tokens), targeted malware campaigns (Harvester deploying a Linux GoGra backdoor using Microsoft Graph/Outlook as covert C2; Lotus Wiper destructive attacks against Venezuelan energy systems; Mustang Panda LOTUSLITE banking‑themed espionage), and infrastructure/IoT flaws (BRIDGE:BREAK in Lantronix/Silex,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ecf7e28177e117e832b44860e75d42e4154ddc58d330bf9bbdbd699c21cce06f
Enrichment time
2026-04-23T01:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain · Baitaphish