Corpus graph previewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

270 nodes467 edgesCold links hydrate here

Supply Chain Incident

Checkmarx Jenkins AST plugin supply-chain compromise

Checkmarx reported that attackers used access traced to the Trivy supply-chain attack to publish malicious developer-tooling artifacts, including a modified Jenkins AST plugin.

ConfidenceHigh
Evidence LevelVendor
Attack StageCi Cd Compromise
Source Artifact DivergenceNo
Attribution ConfidenceLikely

Evidence-Gated Propagation

Propagation Timeline

  1. Checkmarx states that unauthorized GitHub access occurred due to the Trivy supply-chain attack, enabling malicious artifacts including the Jenkins plugin.

Affected Packages

Affected Releases

No structured records.

Repositories

Organizations

Maintainers

No structured records.

Threat Actors

Campaigns

Build Systems

  • Jenkins

Distribution Channels

  • Jenkins Marketplace

Compromised Accounts

  • Checkmarx GitHub repository access

Connected Entities

Attribution Evidence

References