TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
ID: aafd4e84-d14d-5af8-9aba-e944008d4821
STIX ID: report--aafd4e84-d14d-5af8-9aba-e944008d4821
Feed Name: The Hacker News
Threat Score
Checkmarx confirmed that a maliciously modified Jenkins AST plugin was published to the Jenkins Marketplace by the group known as TeamPCP; the report links this incident to a broader supply-chain campaign that previously compromised a KICS Docker image, VS Code extensions, a GitHub Actions workflow, and briefly the Bitwarden CLI npm package to deploy credential-stealing malware, suggesting active exploitation and possible incomplete remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
