TP-2026-1192mediumAI DraftC

Checkmarx Jenkins AST plugin supply-chain compromise

DateMay 9, 2026
Attack TypeSupply ChainSectorTechnology
GeographyGlobal
Threat ActorTeamPCP
AttributionA6
ConfidenceC

Summary

Checkmarx reported that attackers used access traced to the Trivy supply-chain attack to publish malicious developer-tooling artifacts, including a modified Jenkins AST plugin.

Technical Analysis

This access enabled the publication of malicious code to a number of externally distributed artifacts, including VS Code extensions, GitHub Actions workflows, and a Jenkins plugin. Sysdig reported on 2026-03-23 that the same attack pattern subsequently appeared in a second, unrelated GitHub Action for Checkmarx's AST.

Attack Chain

Checkmarx reported that attackers used access traced to the Trivy supply-chain attack to publish malicious developer-tooling artifacts, including a modified Jenkins AST plugin. This access enabled the publication of malicious code to a number of externally distributed artifacts, including VS Code extensions, GitHub Actions workflows, and a Jenkins plugin. Sysdig reported on 2026-03-23 that the same attack pattern subsequently appeared in a second, unrelated GitHub Action for Checkmarx's AST.

Impact Assessment

Available sources do not establish additional facts for this section.

Attribution

Available source evidence connects this incident to actor TeamPCP. Available source evidence connects this incident to campaign TeamPCP Multi-Ecosystem Supply Chain Campaign.

Timeline

Available sources do not establish a complete public timeline.

Remediation & Mitigation

"If you are using Checkmarx Jenkins AST plugin, you need to ensure that you are using the version 2.0.13-829.vc72453fa_1c16 that was published on December 17, 2025 or previously," the cybersecurity company said in a statement over the weekend. The Hacker News reported that Checkmarx released version 2.0.13-848.v76e89de8a_053 on GitHub and the Jenkins Marketplace, and that a Checkmarx spokesperson said the new version addressed the incident concerns.

Sources & References