logo

TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack

ID: aafd4e84-d14d-5af8-9aba-e944008d4821

STIX ID: report--aafd4e84-d14d-5af8-9aba-e944008d4821

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

Checkmarx confirmed that a maliciously modified Jenkins AST plugin was published to the Jenkins Marketplace by the group known as TeamPCP; the report links this incident to a broader supply-chain campaign that previously compromised a KICS Docker image, VS Code extensions, a GitHub Actions workflow, and briefly the Bitwarden CLI npm package to deploy credential-stealing malware, suggesting active exploitation and possible incomplete remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.