PULSE NAME
Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions
WHITE CyberHunter_NL 2026-04-23 Modified: 2026-05-23
21
IOCs
MEDIUM VOLUME
Security firm Checkmarx has been the target of a serious supply chain compromise, according to researchers at the Socket Research Team and the Open Source Software (OSS) in the United States and Canada.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
mcpAddon.js KICS
Indicators of Compromise (4 / 21 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 250f3633529457477a9f8fd3db3472e94383606a 2026-04-23
FileHash-SHA1 2b12cc5cc91ec483048abcbd6d523cdc9ebae3f3 2026-04-23
FileHash-SHA1 bbbca2ddaa5d8feaa63e36b76fdaad77386f024f 2026-04-23
FileHash-SHA1 de0fac2e4500dabe0009e67214ff5f5447ce83dd 2026-04-23