Dossier
Jenkins Marketplace
Coverage of Jenkins Marketplace in the Nexus archive.
- Official CheckMarx Jenkins package compromised with infostealer
A rogue version of Checkmarx's Jenkins Application Security Testing plugin was published on the Jenkins Marketplace, compromising the security of users. The compromised plugin is a version of the official CheckMarx Jenkins package. This incident poses a significant risk to users' sensitive information.
- TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
Checkmarx confirmed a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace after a supply chain attack. Users are advised to use version 2.0.13-829.vc72453fa_1c16 or previously. The incident occurred weeks after the KICS supply chain attack.