Checkmarx Jenkins AST Plugin Supply Chain Compromise — TeamPCP Backdoored Plugin on Jenkins Marketplace — Threadlinqs Intelligence
As of 2026-05-30, Checkmarx Jenkins AST Plugin Supply Chain Compromise — TeamPCP Backdoored Plugin on Jenkins Marketplace is a high-severity supply chain threat attributed to TeamPCP, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0492 · Severity: HIGH · CVSS: 8.6 · Status: MONITORING · Category: SUPPLY_CHAIN
Attribution: TeamPCP · FINANCIAL
Checkmarx disclosed on May 9, 2026 that a modified ('backdoored') version of the Checkmarx Jenkins AST Plugin was distributed via the official Jenkins Marketplace as part of the broader TeamPCP supply
On May 9, 2026 Checkmarx published an update to its 'Ongoing Checkmarx Supply Chain Security Incident' blog warning customers that the Checkmarx Jenkins AST Plugin distributed through the Jenkins Marketplace had been compromised by the same threat cluster — tracked publicly as TeamPCP — that previously trojanized multiple pieces of Checkmarx's developer-tooling estate. The vendor advisory instructs all Jenkins administrators to immediately verify that they are running ONLY the pre-compromise version 2.0.13-829.vc72453fa_1c16 published on 2025-12-17, and to remove or roll back any later release of the plugin until a clean rebuild is published.
The Jenkins AST Plugin integrates Checkmarx Static Application Security Testing into Jenkins CI/CD pipelines. Jenkins agents that execute the plugin typically have access to highly privileged credentials: the Checkmarx tenant API token, source code checkouts, build secrets, container-registry credentials and (in many environments) cloud provider credentials used by downstream pipeline stages. A compromised plugin running on the agent therefore has a near-perfect vantage point for credential harvesting, source code exfiltration and lateral movement into the customer's CI/CD control plane.
The attack pattern observed across the broader TeamPCP campaign is consistent: trojanized releases of legitimate developer-tooling artefacts are pushed to official distribution channels (npm, PyPI, GitHub Actions Marketplace, OpenVSX, Docker Hub, and now Jenkins Marketplace) using either compromised maintainer credentials or compromised vendor build/release infrastructure. The malicious payload typically enumerates the host process for environment variables and well-known credential files, then exfiltrates the data over HTTPS to attacker-controlled infrastructure that impersonates Checkmarx-related domains (checkmarx.zone, checkmarx.cx, audit.checkmarx.cx, updates.checkmarx.cx). Several IP addresses (91.195.240.123, 94.154.172.43, 94.154.172.183) have been linked to TeamPCP infrastructure across earlier compromises.
This Jenkins-plugin compromise is significant because Jenkins remains one of the most widely deployed self-hosted CI/CD orchestrators in regulated industries (financial services, healthcare, critical infrastructure, defense). The Jenkins Marketplace does not enforce strict provenance/SLSA controls equivalent to public registries' newer attestation requirements, which means that downstream operators implicitly trust the named publisher. A malicious release published under the legitimate Checkmarx publisher account would be auto-suggested for upgrade to administrators who have enabled automatic plugin updates — a default configuration in many Jenkins installations.
The Threadlinqs assessment is that exposure is broad and severity is HIGH (with a credible path to CRITICAL impact for organizations whose Jenkins controllers hold cross-environment cloud credentials). Defenders should: (1) pin the plugin to 2.0.13-829.vc72453fa_1c16, (2) rotate any Checkmarx API tokens, source-control PATs, container-registry credentials and cloud credentials accessible from any Jenkins agent that ran a post-2025-12-17 plugin build, (3) hunt for outbound traffic to the known TeamPCP domains/IPs from Jenkins controllers and agents, (4) audit Jenkins plugin update history for the AST Plugin, and (5) treat any Jenkins instance that auto-updated the AST Plugin between 2025-12-17 and 2026-05-09 as a presumed-compromise host pending forensic clearance.
Weaknesses (CWE)
CWE-506, CWE-494, CWE-829, CWE-1357
Target sectors: technology, financial, government, healthcare, defense, critical-infrastructure, software-development
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1583, T1584, T1587, T1195, T1199, T1204, T1059, T1554, T1036, T1553