logo

Checkmarx Jenkins Plugin Backdoored in New TeamPCP Supply Chain Attack

ID: 9df2b488-fc58-5674-ac71-3ad69fc54089

STIX ID: report--9df2b488-fc58-5674-ac71-3ad69fc54089

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ameer Owda

...
...

TeamPCP compromised Checkmarx infrastructure, defacing the Checkmarx Jenkins AST plugin repository and backdooring release 2026.5.09 with a credential-stealing malware ('Shai Hulud'), risking widespread exposure of CI/CD secrets, tokens, and keys for any Jenkins instances that installed the compromised plugin; organizations that used that version should assume compromise, rotate secrets, and audit pipelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.