INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CheckMarx Jenkins package compromised with infostealer

| 2026-05-11 22:03 CRITICAL LOW DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A rogue version of the Checkmarx Jenkins AST plugin was uploaded to [IOC HIDDEN • LOGIN REQUIRED] on Saturday, May 9, 2026. The TeamPCP hacker group claimed responsibility for the compromise and is believed to be behind a series of supply-chain attacks that included the Shai-Hulud campaigns on npm and the Trivy vulnerability scanner breach. At least one company, Checkmarx, has been affected by this incident, with its GitHub repositories compromised allowing access to malicious code published on various platforms including Docker, Open VSX, and VSCode. The malicious plugin was uploaded outside of the official release pipeline and included infostealing malware that compromises user credentials, prompting users to rotate all secrets and investigate for lateral movement or persistence.
Technical Mitigations AI-generated
• Use version 2.0.13-829.vc72453fa_1c16 of the Checkmarx Jenkins AST plugin published on December 17, 2025. • Block or hunt for malicious artifacts uploaded to <a href="/auth/login?next=/detail/oT-3Gp4BqBaeyc0N79Fs" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> by Checkmarx. • Rotate all secrets and investigate for lateral movement or persistence if credentials are compromised.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

re•••••.org
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$ Shai-HuludShai-Hulud
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎2026/05/11
The Checkmarx Jenkins AST plugin was compromised with an infostealer by the TeamPCP hacker group, which uploaded a rogue version to repo.jenkins-ci.org.
infrastructure 2026.5.09
infrastructure 2.0.13-829
threat_actor LAPSUS$
Tactical Metrics
Metrics
infrastructure
‎2026.5.09
Software Version
Metrics
infrastructure
‎2.0.13-829
Software Version
Intelligence Sources
BleepingComputer 2026-05-11