Official CheckMarx Jenkins package compromised with infostealer
ID: 9ac3e06b-35d5-571c-b856-1b013b789b01
STIX ID: report--9ac3e06b-35d5-571c-b856-1b013b789b01
Feed Name: Bleeping Computer
Checkmarx warned that a rogue version of its Jenkins AST plugin was published to the Jenkins Marketplace by the TeamPCP group after the actor gained access to Checkmarx GitHub repositories using credentials stolen in the earlier Trivy supply‑chain compromise. The malicious plugin (2026.5.09) and other modified developer artifacts delivered credential‑stealing malware; Checkmarx advises users to assume credentials are compromised, rotate secrets, investigate lateral movement/persistence, and use published IoCs to detect compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
