The Containment Era is here. →Explore

Executive Summary

In May 2026, Checkmarx's Jenkins Application Security Testing (AST) plugin was compromised by the hacker group TeamPCP. The attackers published a malicious version of the plugin on the Jenkins Marketplace, embedding credential-stealing malware. This breach was facilitated by credentials obtained from a prior supply chain attack on the Trivy vulnerability scanner in March 2026. The malicious plugin, version 2026.5.09, was uploaded on May 9, 2026, and users who installed this version are advised to rotate all secrets and investigate for potential lateral movement or persistence. This incident underscores the escalating trend of supply chain attacks targeting development tools and the critical need for robust security measures in CI/CD pipelines. Organizations must remain vigilant, ensuring the integrity of third-party plugins and promptly addressing any security advisories to mitigate potential risks.

Why This Matters Now

This incident highlights the increasing sophistication of supply chain attacks targeting development tools, emphasizing the urgent need for organizations to enhance their security protocols and ensure the integrity of third-party software components.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Users should immediately uninstall the malicious plugin, rotate all secrets exposed to the Jenkins runner, and investigate their systems for signs of lateral movement or persistence.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit compromised credentials would likely be limited, reducing unauthorized access to critical repositories.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges within the GitHub environment would likely be constrained, reducing the risk of unauthorized modifications.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally into user environments would likely be restricted, reducing the spread of the malicious plugin.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels would likely be detected and disrupted, reducing external communications.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing data loss.

Impact (Mitigations)

The attacker's ability to leverage exfiltrated data for further compromises would likely be limited, reducing the scope of operational disruptions.

Impact at a Glance

Affected Business Functions

  • Continuous Integration/Continuous Deployment (CI/CD) Pipelines
  • Application Security Testing
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of developer credentials, including GitHub tokens, cloud service credentials, and SSH keys.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict access and limit the spread of malicious code within the network.
  • Enhance East-West Traffic Security to monitor and control internal communications, preventing lateral movement of threats.
  • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts.
  • Utilize Multicloud Visibility & Control to gain comprehensive insights into cloud environments and detect anomalous activities.
  • Establish robust Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious behaviors promptly.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image