Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 19, 2026 (about 4 months ago).

people · May 19, 2026

Docker Blog Publishes Analysis of Supply Chain Attacks on Trivy and Checkmarx KICS in 2026

Share the canonical public link.

Share as image

Docker Security team published analysis of supply chain attacks on Trivy and Checkmarx KICS in 2026. On April 22 2026 at 12:35 UTC a threat actor used valid Checkmarx publisher credentials to push malicious images to the checkmarx/kics repository on Docker Hub overwriting five tags and creating two new ones. The images retained legitimate KICS scanning functionality but added covert exfiltration of scan outputs including secrets and credentials to audit.checkmarx.cx. Docker disabled affected digests restored the repository to its March 3 2026 state and suspended the publisher account while notifying users via telemetry.

Below validation threshold — auto-passed without scoring

Supporting evidence