The Checkmarx Jenkins AST plugin compromise is a serious supply-chain warning because Jenkins plugins run inside CI/CD environments where secrets, source code, build credentials, deployment keys, and release workflows often live together like a buffet for attackers. BleepingComputer reports that a rogue version of the official Checkmarx Jenkins AST plugin was published on the Jenkins Marketplace and was used to deliver credential-stealing malware.
Organizations using the plugin should immediately verify the installed version, remove any rogue build, rotate Jenkins credentials, GitHub tokens, cloud keys, registry credentials, signing keys, and deployment secrets that may have been exposed, and review CI/CD logs for suspicious outbound activity. This incident is especially concerning because the threat actor reportedly gained repository access using credentials obtained from an earlier Trivy supply-chain compromise, showing how one stolen secret can become the seed for multiple downstream attacks.
For security teams, this reinforces a painful but necessary point: CI/CD systems must be treated as production-critical security assets, not just developer plumbing. Plugin updates, marketplace trust, secret rotation, least-privilege tokens, signed artifacts, and egress monitoring are now core defenses. Otherwise the build pipeline becomes the attacker’s delivery pipeline, which is efficient, in the same way a trapdoor under your office chair is “space-saving.”
Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. [...]
Source: Official CheckMarx Jenkins package compromised with infostealer via Bleeping Computer — published 11 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.