<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Checkmarx Jenkins Plugin Hit by Supply Chain Attack

Hackers published a malicious Checkmarx Jenkins AST plugin; users urged to update and rotate every credential their CI runners could reach.
Content Team

Checkmarx warned users on May 9 that hackers had published a malicious version of its Jenkins AST plugin — 2026.5.09 — to the Jenkins Marketplace. The plugin, which wires Checkmarx One scanning into Jenkins pipelines, carried a stealer going after crypto wallets, VPN configs, and AWS and GitHub credentials on Windows, Linux and macOS.

The company told users to fall back to version 2.0.13-829.vc72453fa_1c16 from December 2025, then released two newer builds over the weekend; 2.0.13-848.v76e89de8a_053 is now on GitHub and the Jenkins Marketplace. Updating isn't enough on its own — Checkmarx says to rotate every secret its CI runners could reach, from GitHub tokens to cloud and Kubernetes credentials.

The compromise traces back to March's Trivy supply chain attack, which handed TeamPCP the credentials to reach Checkmarx's GitHub repositories. Malicious artifacts followed in late March and again on April 22, and Checkmarx says LAPSUS$ published the stolen data on April 25.

Updated August 13, 2026: Mandiant confirmed the incident contained on June 4, and Checkmarx announced its investigation complete on July 6.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo