Switch language한국어
Back to the list

Checkmarx Jenkins plugin compromised in new supply chain attack

TL;DR AI

Key summary

2 min read
  1. A tampered Checkmarx Jenkins AST plugin was published in the Jenkins Marketplace, affecting version 2026.5.09 with a backdoor.

  2. The attack is linked to TeamPCP and appears to have compromised the plugin repository and release process.

  3. Checkmarx confirmed the incident, assigned CVE-2026-33634, and rated it high severity (CVSS 9.4).

  4. Users should revert to a known safe version immediately and rotate any secrets exposed to the Jenkins runner.

Read the original