logo

TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack

ID: 17db540d-2944-5f16-82a9-74c9e5bec5f0

STIX ID: report--17db540d-2944-5f16-82a9-74c9e5bec5f0

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Tushar Subhra Dutta

...
...

A coordinated supply-chain compromise beginning in March 2026 led to malicious modifications of Checkmarx developer artifacts (including a Jenkins AST plugin published to the Jenkins Marketplace on 2026.5.09) and related tooling (Docker KICS image, GitHub Action, VS Code extensions), enabling credential and secret harvesting across CI/CD and developer environments; Checkmarx confirmed affected artifact hashes, exposed domains/IPs, and recommended rotation of potentially exposed credentials and blocking access to attacker-controlled domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.