Checkmarx’s Weekend Troubles
Once again, Checkmarx finds themselves in a bind as they continue their efforts to remove a dubious version of their Jenkins plugin from the web. Over the weekend, some audacious individual managed to slip in and submit a rogue version of their AST Scanner. This handy tool inspects Jenkins CI pipelines for security issues. By Saturday, May 9, Checkmarx was vocally alerting the public about this sneaky maneuver. They reported that a modified version was floating around on the Jenkins Marketplace.
Be Cautious of Releases from May 9, 2026
The official recommendation is to steer clear of any versions released on or after May 9, 2026. Users are being advised to verify that they are using the correct version, which the more attuned users will know as 2.0.13-829.vc72453fa_1c16, launched on December 17, 2025. There are still several hundred controllers that have adopted this version, and at the time of this writing, it remains the latest one available. However, based on Monday’s pull requests, it appears to be on the fast track to removal.
Trust Concerns with the Jenkins Plugin
“What a sketchy situation,” remarked SOCRadar. The troubling aspect here is the issue of trust. The Checkmarx Jenkins plugin is intended to enhance pipeline security. However, a backdoored version acts like a predator among prey. It can jeopardize every build pipeline it infiltrates, gaining access to source code, environment variables, tokens, and anything else it desires.

TeamPCP Strikes Once More
Security expert Adnan Khan quickly raised the alarm over the weekend. It appears that TeamPCP, those mischievous individuals who have been bothering Checkmarx since April, are back at it. They had a good time spray-painting Checkmarx’s GitHub and posting six packages online, all referencing the Shai-Hulud wormable malware. While those questionable packages have been removed from Checkmarx’s GitHub, TeamPCP went rogue on the AST plugins page, renaming it to “Checkmarx-Fully-Hacked-by-TeamPCP-and-Their-Customers-Should-Cancel-Now” and poking fun at Checkmarx’s security oversights.

The Ongoing Saga
TeamPCP has achieved a hat-trick, successfully exploiting Checkmarx’s packages for the third time in just as many months. Back in March, they targeted Checkmarx’s AST plugin for GitHub Actions and the KICS static analysis tool, managing to sneak in some credential-stealing malware. SOCRadar speculated that this recent attack indicates either TeamPCP was correct about Checkmarx’s security blunders, or they have another clever ploy that the security experts overlooked while hurriedly addressing the March breaches.
Conclusion
Troubles Abound
It seems Checkmarx is in quite a predicament once more, with TeamPCP dragging their name through the mud. Perhaps it’s time for Checkmarx to reassess their internal security measures – or simply change their access codes!

