# Socket Weekly: Checkmarx KICS and Bitwarden CLI Hit in Coordinated…

Canonical: https://brew.new/browse/templates/email/pt1_k97z4ajqxh3papkbzpv9r29vn18e49kp

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: Checkmarx KICS and Bitwarden CLI Hit in Coordinated…](https://cdn.brew.new/email-preview-96494c74ec2677f7-tracking_r57qthbg0khzmgam8dbw7b0cw58dvpwq-1789015367458.png)

## Email content

socket-weekly-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

Checkmarx KICS and Bitwarden CLI Hit in Coordinated Supply Chain Attacks

Checkmarx KICS (Docker images, VS Code extensions) and Bitwarden CLI were both compromised this week, as attackers continue systematically targeting infrastructure-adjacent security tools that sit close to developer credentials and build pipelines. Both compromises shared identical C2 infrastructure and credential harvesting techniques, pointing to coordinated campaign operations.

MORE NEWS

Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware

The CanisterWorm playbook is back, and this time it's hitting AI tooling: Socket detected a postinstall payload in @automagik/genie and pgserve npm packages from Namastex Labs that steals dev secrets, sends them to an Internet Computer canister, and then uses stolen npm tokens to republish itself into more packages.

73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations

We're tracking a cluster of 73 Open VSX sleeper extensions tied to the GlassWorm campaign that are clones of popular developer tools waiting for remote activation. Six clones have already been weaponized through normal update channels, part of a sleeper extension pattern where attackers build credibility before turning them into malware loaders.

MORE WORTH READING

Trivy, KICS, and the shape of supply chain attacks so far in 2026

Inside GitHub's Fake Star Economy

Open Source and the Future of AI

OpenAI Releases GPT‑5.5

AI threats in the wild: The current state of prompt injections on the web

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97z4ajqxh3papkbzpv9r29vn18e49kp)

[Browse email designs](https://brew.new/browse/templates)
