Cybersecurity researchers have discovered that it is possible for attackers to exploit improperly configured Jenkins Script Console for further criminal activities such as crypto mining.
See also: GhostEngine mining attacks kill EDR security

“ Misconfigurations, such as improperly setting up authentication mechanisms, expose the ‘/script’ endpoint to attackers ,” Trend Micro’s Shubham Singh and Sunil Bharti said in a technical report published last week. “ This can lead to remote code execution (RCE) and malicious attacks by hackers. ”
Jenkins Script, a popular continuous integration and continuous delivery (CI/CD) platform, features a Groovy script console, which allows users to execute arbitrary Groovy scripts within the Jenkins controller runtime.
The project maintainers explicitly note that the web-based Groovy shell can be used to read files containing sensitive data (e.g. “/etc/passwd”), decrypt credentials configured in Jenkins, and even reconfigure security settings.
“Granting a regular Jenkins user Script Console access is essentially the same as granting them administrator privileges within Jenkins.“
See also: February 2024: Hackers obtained $105 million worth of crypto through 20 attacks
While access to the Script Console is typically restricted to only authenticated users with administrative privileges, incorrect Jenkins parameters could accidentally make the “/script” (or “/scriptText”) accessible over the internet, making it ripe for exploitation by attackers looking to execute dangerous commands.

Trend Micro said it has identified instances of threats exploiting misconfiguration of the Jenkins Groovy plugin to execute a Base64-encoded containing a malicious script designed for crypto mining on the compromised server, deploying a mining payload.
To protect yourself from such exploitation attempts, it is recommended that you ensure proper configuration, implement strong authentication and authorization, conduct regular audits, and limit public exposure of Jenkins servers to the internet.
The development comes as cryptocurrency thefts resulting from hacks and exploits have increased in the first half of 2024, allowing threat actors to loot $1.38 billion, up from $657 million the previous year.
See also: Hacker created 1 million illegal virtual servers for cryptocurrency mining
Crypto mining attacks, such as the Jenkins Script, also known as cryptojacking, involve the unauthorized use of computer to mine cryptocurrencies. These attacks can infect a variety of devices, including computers, smartphones, and even servers, significantly slowing down performance and increasing power consumption. Cybercriminals typically deploy cryptojacking through malicious websites, phishing emails, or by exploiting vulnerabilities in software. Once embedded, the malware runs silently in the background, draining processing power and potentially damaging hardware over time.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
