MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Compromised Kong Ingress Controller image distributes cryptominer

Kong disclosed that an unauthorized actor compromised its software publication workflow and published a malicious Kong Ingress Controller 3.4.0 Docker image containing a cryptocurrency miner. Legitimate Docker tags pointed to the unauthorized image, which was downloaded 202 times before Kong removed it and rebuilt the release. The compromise therefore propagated malicious code through a legitimate software-distribution channel, constituting a directly evidenced software supply-chain integrity impact.

70

Estimated severity

70 / 100

92

Source reliability

92 / 100

Approximate Date

24/12/2024

Targeted Company

KONG

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseCryptocurrency mining

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.