EPISODE · May 11, 2026 · 0 MIN
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack
from Security Stuff · host Trace3
Cybersecurity firm Checkmarx has warned that a malicious version of its Jenkins AST plugin was published to the Jenkins Marketplace as part of an ongoing supply chain attack. The incident stems from a security breach that began in March when the TeamPCP hacker gang accessed Checkmarx's repositories through a separate Trivy supply chain attack, later followed by data exposure from the Lapsus dollar extortion group. Checkmarx has since released an updated, clean version of the plugin and is urging users to ensure they're running the latest secure iteration available on both GitHub and the Jenkins Marketplace.
Embed this episode
NOW PLAYING
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.