# Jenkins Plugin Supply Chain Attack Underscores Cascading Risk in Developer Tools


A compromised version of Checkmarx's Jenkins Application Security Testing plugin exposed thousands of organizations to credential-stealing malware, marking the latest in a relentless string of supply chain compromises targeting the software development ecosystem.


## The Threat


On May 9, 2026, a malicious version of the Checkmarx Jenkins AST plugin (version 2026.5.09) was published to the official Jenkins Marketplace, potentially exposing developers and security teams worldwide to infostealer malware. The compromise was claimed by TeamPCP, a threat group that has orchestrated a systematic campaign of supply chain attacks over the past two months, compromising critical infrastructure used by millions of developers.


The rogue plugin was distributed through the legitimate Jenkins Marketplace, meaning organizations using automated dependency management systems may have unknowingly pulled the malicious version into their CI/CD pipelines—a nightmare scenario for security teams responsible for securing the build process itself.


According to Checkmarx, the malicious plugin was uploaded outside of the official release pipeline and lacked standard metadata including proper git tags and GitHub release references. The legitimate version users should be running is 2.0.13-829.vc72453fa_1c16, published on December 17, 2025, or any earlier stable release.


## Background and Context


This is not Checkmarx's first brush with TeamPCP. The security firm has now suffered three separate incidents since late March 2026, each revealing failures in credential rotation and access control:


| Incident | Date | Attack Vector | Impact |

|----------|------|---|---------|

| First Breach | Late March 2026 | Trivy vulnerability scanner supply chain | Credentials stolen; used in subsequent attacks |

| KICS Poisoning | Late April 2026 | Malicious versions on Docker, VSCode, Open VSX | Infostealer deployed to developer environments |

| Jenkins Plugin | May 9, 2026 | Rogue plugin in official marketplace | Credential theft at scale in CI/CD pipelines |


The TeamPCP message left in the Checkmarx GitHub repository's about section read: "Checkmarx fails to rotate secrets again. With love - TeamPCP." This taunt carries particular sting because it reveals a cascading failure pattern: once TeamPCP obtained credentials from the Trivy compromise in March, Checkmarx apparently never rotated the GitHub repository access tokens. Those same stolen credentials—unchanged for over a month—allowed the attackers to repeatedly compromise Checkmarx's tools across multiple platforms.


## How the Attack Unfolded


The attack chain illustrates why supply chain security has become the industry's most critical weakness:


1. Initial Compromise (March 2026): TeamPCP attacked the Trivy vulnerability scanner, a widely used open-source project maintained by Aqua Security. The attackers stole credentials that had been used across multiple projects, including Checkmarx's infrastructure.


2. Repository Hijacking (March–May): Using the stolen credentials, TeamPCP gained write access to Checkmarx's GitHub repositories containing the source code for multiple developer tools. Rather than being immediately detected and revoked, these credentials remained valid for over a month.


3. Artifact Poisoning: The attackers pushed malicious code into legitimate tools, publishing infostealer-laden versions to Docker registries, the VSCode Marketplace, Open VSX, and—most critically—the official Jenkins Marketplace.


4. Distribution at Scale: The Jenkins plugin, in particular, reached organizations worldwide because Jenkins is installed at millions of enterprises as the backbone of CI/CD automation. Any developer machine running the compromised plugin would be vulnerable to credential theft.


## Technical Details and Indicators


Although Checkmarx has not disclosed the specific functionality of the infostealer payload, defensive security researchers and the company's threat intelligence team have identified several indicators of compromise (IoCs). Organizations that downloaded version 2026.5.09 of the Checkmarx Jenkins AST plugin should assume the following:


  • Credentials exposed: SSH keys, API tokens, GitHub credentials, database passwords, and cloud credentials stored on the affected system are compromised and must be rotated immediately.
  • Environment variable harvesting: The malware likely captured environment variables commonly used in CI/CD pipelines to store secrets.
  • Lateral movement risk: Developers with access to internal tools or production systems may have provided a pivot point for attackers to move deeper into the organization.

  • The malicious version was easily distinguishable from legitimate releases by its anomalous version number (2026.5.09) and lack of standard release metadata, yet it still passed through the Jenkins Marketplace's ingestion process—raising questions about the marketplace's validation procedures.


    ## Who Is Exposed?


    The risk footprint is substantial:


  • Development teams running the Checkmarx Jenkins AST plugin on any date after May 9, 2026
  • Organizations with automated dependency updates that pulled the malicious plugin without manual review
  • Companies storing credentials in CI/CD environments where the infected plugin executed
  • Supply chain partners of affected organizations whose credentials may have been stolen and used in secondary attacks

  • Checkmarx states that its GitHub repositories are isolated from customer production environments and that no direct customer data was stored in the breached repositories. However, the infostealer's capture of developer credentials could provide attackers with pathways into customer networks through developer accounts.


    ## Implications and Industry Pattern


    This incident exemplifies a critical vulnerability in the modern software supply chain: the concentration of trust in a small number of widely used tools. Jenkins alone is used by millions of organizations globally. An infostealer deployed through a Jenkins plugin reaches development teams at dozens of Fortune 500 companies, hundreds of critical infrastructure organizations, and countless SMBs—all in a single attack.


    The TeamPCP campaign has now targeted:

  • Trivy (open-source vulnerability scanner)
  • Checkmarx's KICS analysis tool
  • Checkmarx's Jenkins plugin
  • npm packages via the Shai-Hulud campaign

  • The group's strategy is clear: identify widely distributed developer tools, compromise them, and use the stolen credentials to compromise downstream targets. Each tool acts as a stepping stone for the next attack.


    ## Recommendations


    For Checkmarx Jenkins Plugin Users:


    1. Immediately verify your installed plugin version via Jenkins' Plugin Manager

    2. Downgrade to version 2.0.13-829.vc72453fa_1c16 (December 17, 2025) or earlier

    3. Rotate all credentials that may have been exposed (API keys, database passwords, SSH keys, cloud credentials)

    4. Audit access logs on internal systems for suspicious activity from affected developer machines

    5. Scan build logs and artifacts for signs of exfiltration or persistence mechanisms


    For All Development Organizations:


  • Implement signed artifact verification before installing plugins or dependencies from any marketplace
  • Use credential scanning tools to detect hardcoded secrets in CI/CD pipelines
  • Enforce credential rotation policies with short TTLs (time-to-live) for GitHub tokens and API keys
  • Adopt artifact signing and verification workflows to catch tampering
  • Monitor CI/CD pipeline activity for unusual network connections or data exfiltration

  • ---


    ## HackWire Analysis


    The Checkmarx breach exposes a foundational problem that security vendors have yet to solve: developer tools occupy a uniquely dangerous position in the supply chain because they operate with extraordinary privilege. A Jenkins plugin executes with access to all secrets configured in your CI/CD environment, all source code being built, all deployment credentials, and all monitoring and logging infrastructure. When such a tool is compromised, the attacker doesn't just get one set of credentials—they get *all of them*.


    What's particularly damaging about TeamPCP's approach is its methodical, opportunistic targeting. Rather than attacking specific verticals or geographies, they systematically compromise widely used tools, then use the stolen credentials to attack the vendors' own infrastructure and customers. Checkmarx's failure to rotate secrets after the Trivy incident is not unusual—it represents a common friction point in incident response. After a third-party breach, rotating all credentials across all systems is operationally expensive and disruptive. But the cost of *not* rotating is exponentially higher, as this incident demonstrates.


    The broader pattern emerging across 2026 is that no single vendor can be the sole trust anchor for your supply chain. Implement defense-in-depth: verify artifacts cryptographically, isolate CI/CD secrets with short-lived credentials, monitor for anomalous exfiltration, and assume that any widely used tool *will eventually be compromised*. The question is not whether your Jenkins installation will be targeted—it's whether you'll detect the compromise before attackers pivot into your network.


    — HackWire Editorial


    ---


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)