people · May 19, 2026
Docker Blog Publishes Analysis of Supply Chain Attacks on Trivy and Checkmarx KICS in 2026
Share the canonical public link.
Docker Security team published analysis of supply chain attacks on Trivy and Checkmarx KICS in 2026. On April 22 2026 at 12:35 UTC a threat actor used valid Checkmarx publisher credentials to push malicious images to the checkmarx/kics repository on Docker Hub overwriting five tags and creating two new ones. The images retained legitimate KICS scanning functionality but added covert exfiltration of scan outputs including secrets and credentials to audit.checkmarx.cx. Docker disabled affected digests restored the repository to its March 3 2026 state and suspended the publisher account while notifying users via telemetry.