Checkmarx Jenkins Plugin Hit by Supply Chain Attack
Want more insights like this?
Checkmarx warned users on May 9 that hackers had published a malicious version of its Jenkins AST plugin — 2026.5.09 — to the Jenkins Marketplace. The plugin, which wires Checkmarx One scanning into Jenkins pipelines, carried a stealer going after crypto wallets, VPN configs, and AWS and GitHub credentials on Windows, Linux and macOS.
The company told users to fall back to version 2.0.13-829.vc72453fa_1c16 from December 2025, then released two newer builds over the weekend; 2.0.13-848.v76e89de8a_053 is now on GitHub and the Jenkins Marketplace. Updating isn't enough on its own — Checkmarx says to rotate every secret its CI runners could reach, from GitHub tokens to cloud and Kubernetes credentials.
The compromise traces back to March's Trivy supply chain attack, which handed TeamPCP the credentials to reach Checkmarx's GitHub repositories. Malicious artifacts followed in late March and again on April 22, and Checkmarx says LAPSUS$ published the stolen data on April 25.
Updated August 13, 2026: Mandiant confirmed the incident contained on June 4, and Checkmarx announced its investigation complete on July 6.
Source: Security Week