We are aware that a modified version of the Checkmarx Jenkins AST plugin was published to the Jenkins Marketplace. We are in the process of publishing a new version of this plug-in.
If you are using Checkmarx Jenkins AST Plugin, you need to ensure that you are using the version 2.0.13-829.vc72453fa_1c16 that was published on Dec. 17, 2025 or previously.
We will continue to updates as we have them available.
Checkmarx Jenkins AST Plugin IOCs (malicious artifacts)
On March 23, 2026, Checkmarx identified a cybersecurity incident originating from the Trivy Supply Chain Attack. The cybersecurity community previously reported on March 19 that the TeamPCP attack affecting the Trivy scanner could potentially be used to harvest credentials from downstream users.
While we are still investigating the incident, we believe this is the likely vector that enabled the attackers to obtain credentials and to gain unauthorized access to our GitHub repositories. As a result of that access, the attackers were able to interact with Checkmarx’s GitHub environment and subsequently publish malicious code to certain artifacts.
As part of our investigation into the incident, we identified that exfiltration of data took place on March 30, 2026. A cybercriminal group subsequently published data related to Checkmarx to the dark web on April 25. Current evidence indicates that this data originated from Checkmarx’s GitHub repositories, and that access to those repositories was facilitated through the initial supply chain attack of March 23, 2026.
Importantly, Checkmarx’s GitHub repositories are maintained separately from our customer production environment. As standard practice, we do not store customer data in our GitHub repository.
Checkmarx has been conducting active containment, investigation, remediation and communication efforts continuously from the first day of the incident.
Malicious Checkmarx artifacts are published. Attacker pushes malicious code directly into the Checkmarx GitHub repository.
Containment, investigation, remediation and communication efforts commenced immediately, and remain ongoing.
A second wave of malicious Checkmarx artifacts are published, indicating continued or renewed attacker access.
LAPSUS$ publicly releases data stamped March 30, nearly one month after the suspected exfiltration of data from the Checkmarx GitHub repository by the attacker.
Upon identification of the incident, Checkmarx commenced a formal investigation and engaged external forensic specialists to support that work.
Initial steps Checkmarx took to contain and remediate the incident included:
Following evidence of further malicious artifacts we took additional steps to strengthen our security posture:
We are now in the final stages of our investigation and confirming that the unauthorised access has been fully contained. We will further on this as soon as we are able.
We have communicated with our customers throughout this process and will continue to provide relevant updates as more information becomes available. Further information, including recommended steps customers can take, is available on our Support Portal or in our Security Updates.
We are writing to inform you of a new development in the ongoing Checkmarx supply chain security incident.
Our investigation, conducted with support from a leading third-party forensic firm, indicates that a cybercriminal group has published data related to Checkmarx to the dark web. Based on current evidence, we believe this data originated from Checkmarx’s GitHub repository, and that access to that repository was facilitated through the initial supply chain attack of March 23, 2026.
Checkmarx’s GitHub repository is maintained separately from our customer production environment. As standard practice, we do not store customer data in our GitHub repository. Our forensic investigation is ongoing and we are actively working to verify the nature and scope of the posted data.
As part of our immediate response, we have locked down access to the affected GitHub repository while the investigation continues.
If we determine that customer information was involved in this incident, we will notify customers and all relevant parties immediately.
We expect to a more detailed update within 24 hours.
If you have questions this incident or need assistance assessing your environment, please open a case via the Support Portal .
On April 22, we communicated with customers a new development in the supply chain security incident that our team is actively investigating and addressing. We deeply value the trust you place in Checkmarx and are committed to keeping our customers informed as we continue to respond.
As part of our immediate response, we retained outside experts and are working around the clock to get to the bottom of this as quickly as possible. In the interim, we are sharing key findings to-date and recommended actions for our customers to take.
Notably, our investigation thus far indicates that the malicious artifacts did not override previously published, known safe versions. Customers using versions or SHAs published prior to the affected timeframes are not affected.
The following artifacts have been identified as potentially affected:
To date, in response to this development we have:
We recommend that our customers take the following steps as soon as possible:
We have received questions from customers running CxSAST on-premise whether their environments are within the scope of this incident. This communication outlines what is, and is not, in scope for your specific environment (Cx SAST on-premises and CxSAST hosted), and the limited circumstance under which you may need to take action.
Based on our investigation to date, the artifacts confirmed as compromised in this incident are externally distributed components associated with Checkmarx One. They are not part of, and are not delivered with, a CxSAST on-premise installation. Specifically:
Although CxSAST on-premise is out of scope for the compromised artifacts, an incident of this nature warrants standard security vigilance regardless of deployment model. Below we outline the specific conditions that would require a CxSAST on-premise customer to take action as a result of this incident.
If your organization independently uses the open-source KICS scanner — specifically by pulling the public KICS image from Docker Hub ( hub.docker.com/r/checkmarx/kics ) outside of any CxSAST or Checkmarx One workflow — we recommend further action if the image was pulled during the affected time window. This image is distinct from the CxSAST product and from the IaC scanning capability built into Checkmarx One.
The compromised KICS image was present on Docker Hub during the following window:
If you did not pull from Docker Hub during this window, you do not need to take further action. If you did, or are uncertain, please verify the image SHA against the list of malicious SHAs in our public advisory and treat any match as a potential compromise of the host that pulled the image and take further action as appropriate.
For most CxSAST on-premise customers, no product-level remediation is required. As precautionary measures aligned with the broader incident, we recommend:
For environment-specific questions, please open a Support case via the Support Portal at support.checkmarx.com .
We will continue to update this page as our investigation progresses.
This is an ongoing investigation. Please continue to monitor the Checkmarx Community Incident Page for more information.
If you have questions this development, please open a case via the Support Portal.
We are grateful for your continued support and patience as we work to address this incident.
On March 23, 2026, Checkmarx identified a cybersecurity supply chain incident affecting certain Checkmarx‑related developer artifacts distributed via third‑party channels.
This post contains a structured overview of the incident and the steps we have taken to date, as well as additional resources to support our clients and team members.
On March 23, 2026, Checkmarx was the target of a cybersecurity supply chain incident which affected two specific plugins distributed via the OpenVSX marketplace and two of our GitHub Actions workflows.
On March 23, 2026, at approximately 02:53 UTC, malicious versions of two plugins were published to the OpenVSX registry.
Only organizations that downloaded the following artifacts from OpenVSX on 23 March, 2026 between 02:53 UTC and 15:41 UTC and ran it are potentially impacted by this incident.
The affected plug-ins are no longer available and all older GitHub versions have been permanently removed.
Plugins downloaded from the VS Code Marketplace were not affected.
The following guidance is provided as a precautionary measure to support customer‑led assessments and remediation, where relevant to their environments.
If a client downloaded and ran either of the above extensions from the Open VSX registry, their organization may be affected.
If the client organization may have been affected, we strongly recommend taking the following steps as soon as possible.
1. Remove Malicious Components
2. Revoke and Rotate Credentials
An issue was also identified in KICS and AST GitHub Action on March 23, 2026. The attacker injected malicious payloads into the following GitHub Actions workflows which were available between 12:58 and 16:50 UTC:
Maintainers revoked the affected tags, securing access, and preventing unauthorized changes.
All GitHub Actions have been updated to the following latest verified releases, and all older versions have been permanently deleted from the organization’s repositories:
Both versions are the only ones available in our repos. All pipelines must reference these versions exclusively or newer.
If you downloaded the malicious versions of either plugin (ast-results-2.53.0.vsix or cx-dev-assist-1.7.0.vsix) from OpenVSX during the affected period, we strongly recommend following these precautionary steps:
Upon identification of the issue, we took immediate steps to contain and remediate the incident. We removed the unauthorized code, pinned our workflows to safe verified commit SHAs, revoked and rotated relevant credentials, blocked outbound access to the attacker-controlled domain, and reviewed our environments for any signs of further compromise.
We have commenced a formal investigation and engaged external forensic specialists to support that work. This investigation is ongoing and includes investigating the behaviour and objectives of the malicious code.
Available information indicates that the primary functionality of the code was focused on the attempted collection and exfiltration of credentials and secrets from affected environments, without evidence to date that such data was successfully exfiltrated from any customer environment.
Based on the investigation to date, and subject to the evidential limitations described below, we recommend continued vigilance and that you notify us promptly if you become aware of any suspicious activity.
While the investigation is ongoing, to date, we do not have evidence indicating that the incident resulted in unauthorised access to customer data or systems, that data held by Checkmarx has been accessed, nor can we yet confirm that any particular customer environment was compromised .
It is important to note that because the affected artefacts execute within customer‑controlled environments, confirmation of whether a particular customer was impacted depends on an assessment of those environments, rather than on telemetry held by Checkmarx. Those CI/CD pipelines and developer workstations are customer‑controlled environments, and Checkmarx does not have independent visibility into their execution or logs.
If you have any questions or need assistance assessing client exposure, please reach out to our security team at [email protected] . Additionally, we have published detailed assessment and remediation guidance, including indicators of compromise, version information and recommended steps for customers on our support portal .
Protecting the security and privacy of our clients and team members is a responsibility we hold to the highest standard. As part of our commitment to transparency, we will provide updates as appropriate and as our investigation progresses.
“Determining whether a specific environment was affected requires a structured assessment across two vectors: CI/CD pipelines and developer workstations.
Assessment — CI/CD pipelines (GitHub Actions):
Assessment – Developer workstations (Open VSX plugins):
Important note regarding Checkmarx scan-based detection:
Executing a Checkmarx SAST or SCA scan against your organization’s codebase will not detect whether your environment was compromised by this incident. The incident involves malicious code executed within a CI/CD runner or IDE environment and does not constitute a vulnerability in application code that a scan would identify. Exposure assessment must be conducted through log analysis, workstation inspection, and credential audit as described above.”
See Checkmarx Security Update, 26 March 2026 ( )
Both checkmarx/ast-github-action and checkmarx/kics-github-action were affected by this incident, as were the two Open VSX Registry plugins referenced in Checkmarx’s security communications.
The following indicators of compromise (IOCs) have been identified through Checkmarx’s investigation and independent third-party security research. The investigation remains ongoing and additional IOCs may be published.
Malicious domain / command-and-control infrastructure:
checkmarx[.]zone – This attacker-controlled domain was intended to be used for the exfiltration of any stolen credentials and secrets. Any outbound DNS query or HTTP/HTTPS connection to this domain originating from CI/CD runners or developer workstations during the affected window should be treated as a confirmed indicator of compromise.
Malicious VSIX filenames (Open VSX):
The specific filenames checkmarx.ast-results-2.53.0.vsix and checkmarx.cx-dev-assist-1.7.0.vsix have been referenced in customer communications. Customers should evaluate any version downloaded from the Open VSX Registry during the affected window, not solely these specific version numbers.
On-disk extension directories:
The presence of Open VSX-sourced Checkmarx extension directories within VS Code’s extension folder constitutes a potential indicator. Refer to FAQ F10 for applicable file paths.
Runner artifacts (setup.sh):
The compromised GitHub Actions injected a script (setup.sh) on the CI/CD runner as part of the action’s initialization sequence. The presence of this script or associated runner artifacts constitutes a behavioral indicator of compromise. The full contents of setup.sh cannot be publicly disclosed at this time given the ongoing investigation.
File hashes (SHA256)- sourced from Wiz threat intelligence reporting:
ast-results-2.53.0.vsix: 65bd72fcddaf938cefdf55b3323ad29f649a65d4ddd6aea09afa974dfc7f105d
cx-dev-assist-1.7.0.vsix: 744c9d61b66bcd2bb5474d9afeee6c00bb7e0cd32535781da188b80eb59383e0
The malicious payload embedded in both the GitHub Actions and the Open VSX plugins was designed to exfiltrate environment variables and secrets from the execution context of the affected GitHub repository.
Credentials at risk – GitHub Actions (CI/CD):
Any secret configured within the affected GitHub repository or organization and accessible to the workflow at the time the compromised action executed is potentially at risk. This includes, but is not limited to: GITHUB_TOKEN, API keys, cloud provider credentials, database credentials, and Checkmarx API tokens.
Credentials at risk – Developer workstations (Open VSX plugin exposure):
Any credential accessible within the VS Code environment, including those stored in environment variables, configuration files, or tokens used by the IDE, should be treated as potentially at risk.
Credentials requiring rotation:
Checkmarx recognizes that many enterprise customers — particularly those in regulated industries or with formal vendor risk management programs — require a written root-cause analysis or incident statement from strategic suppliers following a supply chain security incident such as this.
Checkmarx is commited to providing material updates, and preparing a post-incident report. While the investigation is still ongoing — including with support from a third-party forensic firm we have engaged — we expect the report to include:
The Checkmarx One SaaS platform, including cloud-hosted scanning engines, the Checkmarx One web application, and associated backend services, do not appear to be affected by this incident.
This incident constitutes a supply-chain compromise targeting specific open-source distribution artifacts (GitHub Actions and Open VSX plugins). It does not represent a breach of Checkmarx’s SaaS infrastructure. It does not appear that the threat actor obtained access to Checkmarx One customer tenants, customer data, scan results, or the platform’s internal systems.
Notwithstanding the above, SaaS customers who utilize the affected GitHub Actions (checkmarx/kics-github-action or checkmarx/ast-github-action) within their own CI/CD pipelines, or whose developers installed plugins sourced from the Open VSX Registry, may be indirectly affected.
We understand the residual risk pertains to the customer’s own CI/CD runner environments and developer workstations on which the malicious code may have executed.
Recommended action for SaaS customers:
If your organization does not use checkmarx/kics-github-action or checkmarx/ast-github-action in its GitHub pipelines and developers do not use Open VSX-sourced plugins, no specific action with respect to the SaaS platform is required. If the affected GitHub Actions are in use, any runner that executed those actions during the affected window should be treated as potentially compromised, and customers should follow the remediation guidance including credential rotation, log review, and runner inspection. We recommend heightened vigilance at this time.
Safe versions (post-remediation):
Malicious artifacts were active during March 2026. The precise commencement date remains under investigation. Any pipeline execution or plugin installation or auto-update occurring during this period should be evaluated for potential exposure.
Yes. We have appointed external breach counsel, and a leading forensics expert to assist with our investigation. We are unable to provide an estimated timeline. At this stage, we are notifying regulators and law enforcement as we deem necessary.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
