Checkmarx Jenkins Plugin Backdoored in New TeamPCP Supply Chain Attack
ID: 9df2b488-fc58-5674-ac71-3ad69fc54089
STIX ID: report--9df2b488-fc58-5674-ac71-3ad69fc54089
Feed Name: SOCRadar Blog
Threat Score
TeamPCP compromised Checkmarx infrastructure, defacing the Checkmarx Jenkins AST plugin repository and backdooring release 2026.5.09 with a credential-stealing malware ('Shai Hulud'), risking widespread exposure of CI/CD secrets, tokens, and keys for any Jenkins instances that installed the compromised plugin; organizations that used that version should assume compromise, rotate secrets, and audit pipelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
