Backdoored Jenkins Plugin Hits CI Trust Boundary

A marketplace-listed Jenkins plugin is not just another add-on when it plugs into build and security scanning. A malicious Checkmarx Jenkins AST plugin could sit inside Jenkins pipelines and compromise the trust path used to scan source code through Checkmarx One, so a normal plugin update review can miss that the controller may already have run a poisoned integration layer. Checkmarx said a modified version of the plugin was published to the Jenkins Marketplace and told users to verify they are on 2.0.13-829.vc72453fa_1c16 or newer. It then released 2.0.13-848.v76e89de8a_053 on GitHub and the Marketplace. The incident sits inside a broader supply-chain compromise that Checkmarx says began after Trivy-related credential theft exposed its repositories in March. The risk is not limited to the plugin artifact itself. Any scans, jobs, or credentials handled through that Jenkins and Checkmarx trust path while the malicious version was present may need to be treated as exposed.

Part of the PlainSec briefing for 2026-05-12

Sources