Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
ID: b50fa7e6-03d6-56dc-8858-332a81a3c50e
STIX ID: report--b50fa7e6-03d6-56dc-8858-332a81a3c50e
Feed Name: The Register (Security)
Checkmarx disclosed that a modified (backdoored) version of its Jenkins AST plugin was published to the Jenkins Marketplace by the TeamPCP actors on May 9, 2026; the compromise leverages Mini Shai‑Hulud malware previously observed in large-scale npm and GitHub supply‑chain intrusions. The malicious plugin can propagate into CI pipelines and exfiltrate credentials, environment variables, and source code, and this marks at least the third TeamPCP intrusion affecting Checkmarx components in recent months; users are advised to verify they run the known-good plugin release (2.0.13-829.vc72453fa_1c16) and treat versions published as of May 9 as untrusted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
