Skip to content

TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack

Cybersecuritynews •Tushar Subhra Dutta • May 12, 2026

A supply chain attack that started with a relatively obscure open-source scanner has now reached one of the most widely used application security tools in the industry. In May 2026, a malicious version of the Checkmarx Jenkins AST plugin was quietly published to the Jenkins Marketplace, exposing development pipelines to credential theft and unauthorized access. […]

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)

Tools (1)