Checkmarx confirmed that a modified version of the Jenkins AST plugin has been published on the Jenkins Marketplace.

“ If you are using the Checkmarx Jenkins AST plugin, you should ensure you are using version 2.0.13-829.vc72453fa_1c16 released on or before December 17, 2025 ,” the cybersecurity firm said over the weekend
Checkmarx has now released version 2.0.13-848.v76e89de8a_053 to both GitHub and the Jenkins Marketplace, although its update regarding the incident still states thatit is “in the process of publishing a new version of this plugin.”
See also: cPanel vulnerability used to distribute Filemanager Backdoor
The company did not disclose how the malicious version of the plugin was released, but this development is reportedly the latest attack organized by TeamPCP targeting Checkmarx.
TeamPCP attacks
A few weeks ago, the group was also linked to the compromise of a KICS Docker image, two VS Code extensions , and a GitHub Actions workflow to promote credential stealing malware. The breach, in turn, led to the brief compromise of the Bitwarden CLI npm package to distribute a similar stealer that can harvest a wide range of developer secrets.
TeamPCP has been linked to a series of breaches since March 2026, which are allegedly part of an extensive campaign that exploits the inherent trust in the software supply chainto spread malware.
Checkmarx: Jenkins AST plugin breach
According to details shared by security researcher Adnan Khan and SOCRadar, TeamPCP allegedly gained unauthorized access to the Jenkins AST plugin and renamed it “Checkmarx-Fully-Hacked-by-TeamPCP-and-Their-Customers-Should-Cancel-Now”.
See also: Linux: "Safety switch" proposed to protect against zero-day vulnerabilities

The modified repository was also updated to include the description: “Checkmarx fails to rotate secrets again. with love – TeamPCP.”
“The fact that TeamPCP returned to Checkmarx’s systems just a few weeks later suggests one of two possibilities: either the initial remediation was incomplete and did not fully rotate credentials, or the team maintained an entry point that was not recognized during the March response,” SOCRadar reported. “A second Checkmarx incident occurring so soon suggests that the team is actively monitoring reentry points, testing the depth of previous remediations, and exploiting any gaps.”
The new incident with the Jenkins AST plugin confirms that attacks on the software supply chain are evolving into one of the biggest threats to the modern world of development and DevOps. The Checkmarx case and the action of TeamPCP show how easily an attacker can exploit the trust in tools, plugins and automated software development processes, distributing malicious code through seemingly trustworthy sources. The fact that the same group is already linked to breaches in GitHub Actions, Docker images, VS Code extensions and npm packages reveals a highly organized and aggressive campaign targeting developers and corporate infrastructure.
See also: TrickMo banking malware for Android adopts TON blockchain

Cybersecurity experts predict that such attacks will continue to increase as CI/CD infrastructures and open-source ecosystems become a critical part of global software production. For enterprises, protection is not limited to installing updates, but requires continuous access control, regular credential rotation, repositories monitoring, and strict verification of packages used in development processes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The Checkmarx case serves as yet another warning that even cybersecurity companies can find themselves targeted by sophisticated threat groups when supply chain security is not treated as an absolute priority.
