Checkmarx Jenkins Plugin Compromised in Supply-Chain Attack
🔒 Checkmarx warned that a rogue version of its Jenkins AST plugin was published to the Jenkins Marketplace and contained credential-stealing malware attributed to the TeamPCP threat group. The attackers used credentials obtained in a prior Trivy supply-chain breach to backdoor multiple developer tools and maintain access. Checkmarx is publishing a clean plugin release, advising users to revert to version 2.0.13-829.vc72453fa_1c16, rotate secrets, and investigate for compromise.
