National Cyber Warfare Foundation (NCWF)

Checkmarx Jenkins AST Plugin Compromised in KICS Supply Chain Attack


0 user ratings
2026-05-12 05:57:05
milo
Red Team (CNA)

Supply chain campaign has now extended to Checkmarx’s Jenkins ecosystem, with attackers pushing a malicious Checkmarx Jenkins AST plugin to the official Jenkins Marketplace as part of the ongoing KICS/Trivy-linked compromise. The rogue release is identified as version 2026.5.09 and includes tampered plugin artifacts, while the last known-good Jenkins AST plugin build remains 2.0.13-829.vc72453fa_1c16, released […]


The post Checkmarx Jenkins AST Plugin Compromised in KICS Supply Chain Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Mayura Kathir

Source: gbHackers
Source Link: https://gbhackers.com/checkmarx-jenkins-ast-plugin/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.