Vulnerabilità · 142 giorni fa
Un plugin Jenkins elencato nel marketplace non è solo un altro add-on quando si integra con build e security scanning. Un plugin Checkmarx Jenkins AST malevolo potrebbe trovarsi all'interno delle pipeline Jenkins e compromettere il trust path usato per scansionare il codice sorgente tramite Checkmarx One, quindi una normale review dell'update del plugin può non rilevare che il controller possa già aver eseguito un integration layer avvelenato.
4 fonti che coprono questa storia
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
TeamPCP compromised a Checkmarx Jenkins plugin in 2026, exposing supply chain security gaps and credential risks.
Official CheckMarx Jenkins package compromised with infostealer
Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace.
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
Cybercrooks ruin engineers' weekends with Saturday attack
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack
A malicious version of the plugin was published to the Jenkins Marketplace late last week.
Part of the PlainSec briefing for 2026-05-12