A malicious version of the Checkmarx Jenkins plugin slipped onto the official Jenkins Marketplace, sitting right inside the build pipelines that companies trust to scan their own code for vulnerabilities.