logo

Official CheckMarx Jenkins package compromised with infostealer

ID: 9ac3e06b-35d5-571c-b856-1b013b789b01

STIX ID: report--9ac3e06b-35d5-571c-b856-1b013b789b01

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Bill Toulas

...
...

Checkmarx warned that a rogue version of its Jenkins AST plugin was published to the Jenkins Marketplace by the TeamPCP group after the actor gained access to Checkmarx GitHub repositories using credentials stolen in the earlier Trivy supply‑chain compromise. The malicious plugin (2026.5.09) and other modified developer artifacts delivered credential‑stealing malware; Checkmarx advises users to assume credentials are compromised, rotate secrets, investigate lateral movement/persistence, and use published IoCs to detect compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.