Checkmarx Jenkins plugin compromised in new supply chain attack

TL;DR AI
2 min readKey summary
A tampered Checkmarx Jenkins AST plugin was published in the Jenkins Marketplace, affecting version 2026.5.09 with a backdoor.
The attack is linked to TeamPCP and appears to have compromised the plugin repository and release process.
Checkmarx confirmed the incident, assigned CVE-2026-33634, and rated it high severity (CVSS 9.4).
Users should revert to a known safe version immediately and rotate any secrets exposed to the Jenkins runner.
