Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Upgrade the Checkmarx Jenkins AST plugin to version 2.0.13‑829.vc72453fa_1c16 or earlier.
Upgrade the Checkmarx Jenkins AST plugin to version 2.0.13‑829.vc72453fa_1c16 or earlier.
Summary
In a recent supply‑chain breach, the TeamPCP hacker group released a rogue version of Checkmarx’s Jenkins AST plugin (2026.5.09) to the Jenkins Marketplace. The malicious build contains credential‑stealing malware that can harvest secrets from developers’ environments. The attack follows TeamPCP’s earlier theft of Checkmarx’s GitHub credentials during the Trivy supply‑chain incident.
Checkmarx’s official plugin, version 2.0.13‑829.vc72453fa_1c16, was published on December 17 2025 and remains the only trusted release. The rogue plugin was injected outside the normal release pipeline, lacking a git tag and proper release metadata, allowing attackers to bypass standard verification checks and distribute the malware to unsuspecting users.
The company has issued a security advisory urging all users to install the verified plugin and to rotate any credentials that may have been exposed. Checkmarx also recommends conducting a thorough investigation for lateral movement within affected environments. Indicators of compromise have been released to help defenders detect and mitigate the threat.
Although the malware can harvest credentials, Checkmarx confirmed that no customer data was stored in its GitHub repositories and no evidence of customer data exfiltration has been found. Nonetheless, the incident highlights the risks of supply‑chain attacks and the importance of strict verification processes for third‑party plugins.
Industry experts stress that organizations must adopt robust supply‑chain security practices, including continuous monitoring of plugin repositories, strict version control, and the use of signed artifacts. The TeamPCP attack serves as a stark reminder that even well‑established security tools can become vectors for credential theft if their distribution channels are compromised.
Key changes
- Checkmarx released a modified version of the Jenkins AST plugin to the Jenkins Marketplace.
- The safe version is 2.0.13‑829.vc72453fa_1c16, published December 17 2025.
- Users must ensure they are running this or an earlier unmodified release.
- The modified build contained unexpected code changes flagged by a security audit.
- Checkmarx issued a statement urging verification of plugin version before deployment.