• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Provide Chain Assault

Admin by Admin
May 11, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananMight 11, 2026Provide Chain Assault / DevSecOps

Checkmarx has confirmed {that a} modified model of the Jenkins AST plugin was printed to the Jenkins Market.

“If you’re utilizing Checkmarx Jenkins AST plugin, it is advisable to guarantee that you’re utilizing the model 2.0.13-829.vc72453fa_1c16 that was printed on December 17, 2025 or beforehand,” the cybersecurity firm mentioned in an announcement over the weekend.

As of writing, Checkmarx has launched 2.0.13-848.v76e89de8a_053 on each GitHub and the Jenkins Market, though its incident replace nonetheless notes that it is “within the means of publishing a brand new model of this plugin.” It didn’t disclose how the malicious plugin model was printed.

The event is the newest assault orchestrated by TeamPCP concentrating on Checkmarx. It arrives a few weeks after the infamous cybercrime group was attributed to the compromise of its KICS Docker picture, two VS Code extensions, and a GitHub Actions workflow to push credential-stealing malware.

The breach, in flip, resulted within the temporary compromise of the Bitwarden CLI npm package deal to serve the same stealer that may harvest a variety of developer secrets and techniques.

TeamPCP has been linked to a collection of breaches since March 2026 as a part of a sprawling marketing campaign that exploits the inherent belief within the software program provide chain to propagate its malware and increase its attain.

In keeping with particulars shared by safety researcher Adnan Khan and SOCRadar, TeamPCP is alleged to have gained unauthorized entry to the plugin’s GitHub repository and renamed it to “Checkmarx-Absolutely-Hacked-by-TeamPCP-and-Their-Clients-Ought to-Cancel-Now.”

The defaced repository was additionally up to date to incorporate the outline: “Checkmarx fails to rotate secrets and techniques once more. with love – TeamPCP.”

“The truth that TeamPCP is again inside Checkmarx techniques simply weeks later factors to one among two potentialities: both the preliminary remediation was incomplete and credentials weren’t absolutely rotated, or the group retained a foothold that wasn’t recognized through the March response,” SOCRadar mentioned.

“A second Checkmarx incident taking place this quickly suggests the group is actively looking ahead to re-entry factors, testing the depth of previous remediations, and capitalizing on any gaps.”

Tags: ASTAttackChainCheckmarxCompromisesJenkinsKICSPluginSupplyTeamPCPWeeks
Admin

Admin

Next Post
Understanding LLM Distillation Methods  – MarkTechPost

Understanding LLM Distillation Methods  - MarkTechPost

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Apple’s dealing with of vibe coding apps attracts complaints from startups like Replit and Something that iOS App Retailer guidelines for his or her apps are utilized erratically (Michael Acton/Monetary Instances)

Apple’s dealing with of vibe coding apps attracts complaints from startups like Replit and Something that iOS App Retailer guidelines for his or her apps are utilized erratically (Michael Acton/Monetary Instances)

May 4, 2026
Use Instances, Varieties, and Challenges

Use Instances, Varieties, and Challenges

June 4, 2025

Trending.

Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

April 29, 2026
Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

April 21, 2026
The way to Clear up the Wall Puzzle in The place Winds Meet

The way to Clear up the Wall Puzzle in The place Winds Meet

November 16, 2025
Undertaking possession (fairness and fairness)

Your work diary | Seth’s Weblog

May 6, 2026
The Obtain: the tech reshaping IVF and the rise of balcony photo voltaic

The Obtain: the tech reshaping IVF and the rise of balcony photo voltaic

May 7, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Satan Could Cry Netflix Creator Has Good Recommendation For Bloodborne Film Workforce

Satan Could Cry Netflix Creator Has Good Recommendation For Bloodborne Film Workforce

May 12, 2026
Finest Generative AI Instruments You Ought to Strive in 2026

Finest Generative AI Instruments You Ought to Strive in 2026

May 11, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved