Tag: Jenkins Application Security Testing (AST)

Official CheckMarx Jenkins package compromised with infostealer
News

Official CheckMarx Jenkins package compromised with infostealer

Over the weekend, Checkmarx issued a warning regarding the publication of a rogue version of its Jenkins Application Security Testing (AST) plugin on the Jenkins Marketplace. The TeamPCP hacker organization claimed the penetration and launched a series of supply-chain assaults, including the Shai-Hulud campaigns against npm and the Trivy vulnerability scanner breach, which led to the distribution of malware that steals credentials. One of the most popular Continuous Integration/Continuous Deployment (CI/CD) automation tools for software development, testing, code scanning, application packaging, and server update deployment is Jenkins. Security scanning is included into automated pipelines by the Jenkins Marketplace's Checkmarx AST plugin. We are aware that the Jenkins Marketplac...