TeamPCP Targets Checkmarx Jenkins Plugin After KICS Breach
ID: 0a00a8a3-b9e5-5c79-bd94-4f8e1d0315e4
STIX ID: report--0a00a8a3-b9e5-5c79-bd94-4f8e1d0315e4
Feed Name: Cyber Press
Threat Score
A coordinated supply-chain attack attributed to TeamPCP compromised the Trivy scanner and then pushed a malicious Checkmarx Jenkins AST plugin update (2026.5.09) that silently harvested CI/CD environment variables and cloud credentials; stolen data was later published by LAPSUS$. The report includes IOCs (filenames and SHA-256 hashes) and urges immediate scanning, removal, and blocking of malicious domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
