04/24/2026
Checkmarx has been compromised again — for the second time in just one month.
Attackers injected credential-stealing malware into widely used developer tools, including KICS images on Docker Hub and Visual Studio Code extensions.
Because these tools are trusted and integrated directly into development workflows, this turns into a dangerous supply chain attack — putting developer credentials, systems, and organizations at risk.
This is a reminder that modern attacks don’t break in… they get installed.
🔐 If you’re a developer:
• Review your installed tools
• Rotate credentials immediately
• Stay alert for unusual activity