WhisperX tag archive

#Checkmarx

This page collects WhisperX intelligence signals tagged #Checkmarx. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-05-11 12:10:32 · SecurityWeek RSS

1. Malicious Checkmarx Jenkins Plugin Published to Jenkins Marketplace in Supply Chain Attack

A compromised version of the Checkmarx Jenkins AST Plugin was published to the Jenkins Marketplace late last week, security researchers confirmed. The incident marks another addition to a growing list of supply chain attacks targeting open-source development ecosystems and software build pipelines. While details about ...

The Lab · 2026-05-11 21:48:28 · The Hacker News Echo RSS

2. TeamPCP Injects Compromised Version Into Checkmarx Jenkins AST Plugin on Jenkins Marketplace

Checkmarx has confirmed a supply chain compromise targeting its Jenkins AST plugin, with a malicious version successfully published to the Jenkins Marketplace by an actor identified as TeamPCP. The incident follows a separate supply chain attack on Checkmarx's KICS (Keeping Infrastructure as Code Secure) tool just week...