Compromise of Checkmarx Jenkins AST Plugin by TeamPCP (Campaign)
ID: ba442de2-027c-5eba-ab45-adf19d3bee01
STIX ID: report--ba442de2-027c-5eba-ab45-adf19d3bee01
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-05-09
Date Updated: 2026-05-21
Author: [email protected] (Wiz Threat Research)
Attackers identified as TeamPCP compromised internal resources and publishing credentials to distribute a malicious update to the Checkmarx AST Scanner Jenkins Plugin via the official channel; the update contained a backdoored cli.js that exfiltrated Jenkins credentials, and attackers temporarily controlled a related GitHub repository exposing sensitive data (including a revoked PAT).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
