Checkmarx Knacks TeamPCP Once More: Jenkins Plugin Faces Damage

Checkmarx Knacks TeamPCP Once More: Jenkins Plugin Faces Damage

Checkmarx’s Weekend Troubles

Once again, Checkmarx finds themselves in a bind as they continue their efforts to remove a dubious version of their Jenkins plugin from the web. Over the weekend, some audacious individual managed to slip in and submit a rogue version of their AST Scanner. This handy tool inspects Jenkins CI pipelines for security issues. By Saturday, May 9, Checkmarx was vocally alerting the public about this sneaky maneuver. They reported that a modified version was floating around on the Jenkins Marketplace.

Be Cautious of Releases from May 9, 2026

The official recommendation is to steer clear of any versions released on or after May 9, 2026. Users are being advised to verify that they are using the correct version, which the more attuned users will know as 2.0.13-829.vc72453fa_1c16, launched on December 17, 2025. There are still several hundred controllers that have adopted this version, and at the time of this writing, it remains the latest one available. However, based on Monday’s pull requests, it appears to be on the fast track to removal.

Trust Concerns with the Jenkins Plugin

“What a sketchy situation,” remarked SOCRadar. The troubling aspect here is the issue of trust. The Checkmarx Jenkins plugin is intended to enhance pipeline security. However, a backdoored version acts like a predator among prey. It can jeopardize every build pipeline it infiltrates, gaining access to source code, environment variables, tokens, and anything else it desires.

Checkmarx Knacks TeamPCP Once More: Jenkins Plugin Faces Damage

TeamPCP Strikes Once More

Security expert Adnan Khan quickly raised the alarm over the weekend. It appears that TeamPCP, those mischievous individuals who have been bothering Checkmarx since April, are back at it. They had a good time spray-painting Checkmarx’s GitHub and posting six packages online, all referencing the Shai-Hulud wormable malware. While those questionable packages have been removed from Checkmarx’s GitHub, TeamPCP went rogue on the AST plugins page, renaming it to “Checkmarx-Fully-Hacked-by-TeamPCP-and-Their-Customers-Should-Cancel-Now” and poking fun at Checkmarx’s security oversights.

Checkmarx Knacks TeamPCP Once More: Jenkins Plugin Faces Damage

The Ongoing Saga

TeamPCP has achieved a hat-trick, successfully exploiting Checkmarx’s packages for the third time in just as many months. Back in March, they targeted Checkmarx’s AST plugin for GitHub Actions and the KICS static analysis tool, managing to sneak in some credential-stealing malware. SOCRadar speculated that this recent attack indicates either TeamPCP was correct about Checkmarx’s security blunders, or they have another clever ploy that the security experts overlooked while hurriedly addressing the March breaches.

Conclusion

Troubles Abound

It seems Checkmarx is in quite a predicament once more, with TeamPCP dragging their name through the mud. Perhaps it’s time for Checkmarx to reassess their internal security measures – or simply change their access codes!