Docker Hub Supply Chain Attack: Checkmarx KICS Compromised via Stolen Credentials
Docker reported a supply chain compromise involving the Checkmarx KICS repository on Docker Hub, occurring on April 22, 2026. Threat actors utilized stolen publisher credentials to push malicious images, overwriting five existing tags and creating two new ones. The compromised binaries maintained legitimate scanning functionality while exfiltrating sensitive data, such as secrets and cloud topology, to attacker-controlled infrastructure. Docker confirmed its own infrastructure remained secure, attributing the breach solely to credential theft. This incident follows a similar attack on Trivy, highlighting a growing trend of low-sophistication supply chain attacks leveraging stolen access. Docker suspended the compromised account, restored the repository to a safe state, and notified affected users. Experts advise immediate credential rotation, purging local caches of malicious digests, and pinning CI pipelines to specific image digests rather than mutable tags to prevent future silent overwrites. The event underscores the critical need for layered defense strategies and rapid collaboration between platform providers and security firms like Socket to detect anomalies in provenance and publishing behavior.
Wire timeline
Docker Hub Supply Chain Attack: Checkmarx KICS Compromised via Stolen Credentials
Docker reported a supply chain compromise involving the Checkmarx KICS repository on Docker Hub, occurring on April 22, 2026. Threat actors utilized stolen publisher credentials to push malicious images, overwriting five existing tags and creating two new ones. The compromised binaries maintained legitimate scanning functionality while exfiltrating sensitive data, such as secrets and cloud topology, to attacker-controlled infrastructure. Docker confirmed its own infrastructure remained secure, attributing the breach solely to credential theft. This incident follows a similar attack on Trivy, highlighting a growing trend of low-sophistication supply chain attacks leveraging stolen access. Docker suspended the compromised account, restored the repository to a safe state, and notified affected users. Experts advise immediate credential rotation, purging local caches of malicious digests, and pinning CI pipelines to specific image digests rather than mutable tags to prevent future silent overwrites. The event underscores the critical need for layered defense strategies and rapid collaboration between platform providers and security firms like Socket to detect anomalies in provenance and publishing behavior.
Docker