{"id":877,"date":"2026-05-11T19:33:27","date_gmt":"2026-05-11T19:33:27","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=877"},"modified":"2026-05-11T19:33:27","modified_gmt":"2026-05-11T19:33:27","slug":"teampcp-compromises-checkmarx-jenkins-ast-plugin-weeks-after-kics-supply-chain-attack","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=877","title":{"rendered":"TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 11, 2026<\/span><\/span><span class=\"p-tags\">Supply Chain Attack \/ DevSecOps<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiq0A3_8O89uC968dpFnFxE4v3J4fpr5nEqC-2QiSJ_rtZlgPocPYIaowCvCMeONhcrFiaoSdBVeNsuTa2ipAZZ3HBMUDcfO8DZ06pughteYJItHhMLeBr_jnfLL-5WX6xBE_EjIfPDGjCYyDCa6aImjimPNl7FtM1evdnTUVEk54x9pczRaFlmEZy1Cv8B\/s1700-e365\/Jenkins.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Checkmarx has confirmed that a modified version of the <a href=\"https:\/\/plugins.jenkins.io\/checkmarx-ast-scanner\/\">Jenkins AST plugin<\/a> was published to the Jenkins Marketplace.<\/p>\n<p>\u00abIf you are using Checkmarx Jenkins AST plugin, you need to ensure that you are using the version 2.0.13-829.vc72453fa_1c16 that was published on December 17, 2025 or previously,\u00bb the cybersecurity company <a href=\"https:\/\/checkmarx.com\/blog\/ongoing-security-updates\/\">said<\/a> in a statement over the weekend.<\/p>\n<p>As of writing, Checkmarx has released 2.0.13-848.v76e89de8a_053 on both GitHub and the Jenkins Marketplace, although its incident update still notes that it&#8217;s \u00abin the process of publishing a new version of this plugin.\u00bb It did not disclose how the malicious plugin version was published.<\/p>\n<p>The development is the latest attack orchestrated by TeamPCP targeting Checkmarx. It arrives a couple of weeks after the notorious cybercrime group was attributed to the compromise of its KICS Docker image, two VS Code extensions, and a GitHub Actions workflow to push credential-stealing malware.<\/p>\n<p>The breach, in turn, resulted in the brief compromise of the Bitwarden CLI npm package to serve a similar stealer that can harvest a wide range of developer secrets.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>TeamPCP has been linked to a series of breaches since March 2026 as part of a sprawling campaign that exploits the inherent trust in the software supply chain to propagate its malware and expand its reach.<\/p>\n<p>According to details shared by security researcher <a href=\"https:\/\/x.com\/adnanthekhan\/status\/2053156381616676928\">Adnan Khan<\/a> and <a href=\"https:\/\/socradar.io\/blog\/checkmarx-jenkins-plugin-teampcp-backdoor\/\">SOCRadar<\/a>, TeamPCP is said to have gained unauthorized access to the plugin&#8217;s GitHub repository and renamed it to \u00abCheckmarx-Fully-Hacked-by-TeamPCP-and-Their-Customers-Should-Cancel-Now.\u00bb<\/p>\n<p>The defaced repository was also updated to include the description: \u00abCheckmarx fails to rotate secrets again. with love \u2013 TeamPCP.\u00bb<\/p>\n<p>\u00abThe fact that TeamPCP is back inside Checkmarx systems just weeks later points to one of two possibilities: either the initial remediation was incomplete and credentials were not fully rotated, or the group retained a foothold that wasn&#8217;t identified during the March response,\u00bb SOCRadar said.<\/p>\n<p>\u00abA second Checkmarx incident happening this soon suggests the group is actively watching for re-entry points, testing the depth of past remediations, and capitalizing on any gaps.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 11, 2026Supply Chain Attack \/ DevSecOps Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. \u00abIf you are using&hellip;<\/p>\n","protected":false},"author":1,"featured_media":878,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1604,220,219,857,173,1603,1363,1258,218,855,1605],"class_list":["post-877","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-ast","tag-attack","tag-chain","tag-checkmarx","tag-compromises","tag-jenkins","tag-kics","tag-plugin","tag-supply","tag-teampcp","tag-weeks"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/877","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=877"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/877\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/878"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=877"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=877"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=877"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}