


Perceptive Security
SOC/SIEM Consultancy

Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags
Published:
23 maart 2026 om 23:05:11
Alert date:
24 maart 2026 om 09:16:39
Source:
stepsecurity.io
Supply Chain & Dependencies, Security Tools
The Checkmarx KICS GitHub Action repository has been compromised with malware injected into all release tags. An infostealer payload was embedded across all versions of the kics-github-action repository. Organizations using any version of this GitHub Action should immediately treat their CI/CD secrets as compromised. This represents a significant supply chain attack targeting development and deployment pipelines. Immediate secret rotation is required for all affected environments. The compromise affects the entire release history of the popular security scanning tool.
Technical details
Mitigation steps:
Affected products:
Checkmarx KICS GitHub Action
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
