Vulnerabilities · 126 days ago
A marketplace-listed Jenkins plugin is not just another add-on when it plugs into build and security scanning. A malicious Checkmarx Jenkins AST plugin could sit inside Jenkins pipelines and compromise the trust path used to scan source code through Checkmarx One, so a normal plugin update review can miss that the controller may already have run a poisoned integration layer.
Checkmarx said a modified version of the plugin was published to the Jenkins Marketplace and told users to verify they are on 2.0.13-829.vc72453fa_1c16 or newer. It then released 2.0.13-848.v76e89de8a_053 on GitHub and the Marketplace. The incident sits inside a broader supply-chain compromise that Checkmarx says began after Trivy-related credential theft exposed its repositories in March.
The risk is not limited to the plugin artifact itself. Any scans, jobs, or credentials handled through that Jenkins and Checkmarx trust path while the malicious version was present may need to be treated as exposed.
4 sources covering this story
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
TeamPCP compromised a Checkmarx Jenkins plugin in 2026, exposing supply chain security gaps and credential risks.
Official CheckMarx Jenkins package compromised with infostealer
Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace.
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
Cybercrooks ruin engineers' weekends with Saturday attack
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack
A malicious version of the plugin was published to the Jenkins Marketplace late last week.
Part of the PlainSec briefing for 2026-05-12