Supply Chain Incident
Checkmarx Jenkins AST plugin supply-chain compromise
Checkmarx reported that attackers used access traced to the Trivy supply-chain attack to publish malicious developer-tooling artifacts, including a modified Jenkins AST plugin.
Evidence-Gated Propagation
Propagation Timeline
- Packageaquasecurity/trivy-actionCausalPackagecheckmarx-ast-scanner
Checkmarx states that unauthorized GitHub access occurred due to the Trivy supply-chain attack, enabling malicious artifacts including the Jenkins plugin.
Affected Packages
Affected Releases
No structured records.
Repositories
Organizations
Maintainers
No structured records.
Threat Actors
Campaigns
Build Systems
- Jenkins
Distribution Channels
- Jenkins Marketplace
Compromised Accounts
- Checkmarx GitHub repository access
Connected Entities
- CheckmarxOrganization
- Checkmarx GitHub repository accessCompromised Account
- checkmarx-ast-scannerPackage
- JenkinsBuild System
- Jenkins MarketplaceDistribution Channel
- jenkinsci/checkmarx-ast-scanner-pluginRepository
- TeamPCPThreat Actor
- TeamPCP Multi-Ecosystem Supply Chain CampaignCampaign
Attribution Evidence
The Hacker News and Sysdig report the Checkmarx developer-tooling compromise as part of TeamPCP supply-chain activity.
The Checkmarx Jenkins plugin compromise is modeled in the TeamPCP multi-ecosystem campaign because public reporting links it to the Trivy-to-Checkmarx chain.
References
- Update: Ongoing Checkmarx Supply Chain Security IncidentCheckmarx · 2026-06-01
- TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain AttackThe Hacker News · 2026-05-11
- TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub ActionsSysdig Threat Research Team · 2026-03-27