logo

Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged

ID: b50fa7e6-03d6-56dc-8858-332a81a3c50e

STIX ID: report--b50fa7e6-03d6-56dc-8858-332a81a3c50e

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

...
...

Checkmarx disclosed that a modified (backdoored) version of its Jenkins AST plugin was published to the Jenkins Marketplace by the TeamPCP actors on May 9, 2026; the compromise leverages Mini Shai‑Hulud malware previously observed in large-scale npm and GitHub supply‑chain intrusions. The malicious plugin can propagate into CI pipelines and exfiltrate credentials, environment variables, and source code, and this marks at least the third TeamPCP intrusion affecting Checkmarx components in recent months; users are advised to verify they run the known-good plugin release (2.0.13-829.vc72453fa_1c16) and treat versions published as of May 9 as untrusted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.