Skip to content

Checkmarx Jenkins AST Plugin Compromised in KICS Supply Chain Attack

Gbhackers •Mayura Kathir • May 12, 2026

Supply chain campaign has now extended to Checkmarx’s Jenkins ecosystem, with attackers pushing a malicious Checkmarx Jenkins AST plugin to the official Jenkins Marketplace as part of the ongoing KICS/Trivy-linked compromise. The rogue release is identified as version 2026.5.09 and includes tampered plugin artifacts, while the last known-good Jenkins AST plugin build remains 2.0.13-829.vc72453fa_1c16, released […]

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)

Tools (2)