Checkmarx Jenkins AST Plugin Compromised by TeamPCP

Checkmarx has alerted users about a compromised version of its Jenkins AST plugin that was found on the Jenkins Marketplace.

3 min readCybersecurity

Checkmarx has issued a warning regarding a tampered version of its Jenkins AST plugin that surfaced on the Jenkins Marketplace. Users are advised to verify that they are using the correct version, specifically 2.0.13-829.vc72453fa_1c16, which was released on December 17, 2025, or any earlier version. This alert follows a recent incident involving a supply chain attack attributed to TeamPCP, raising concerns about the security of third-party plugins. The cybersecurity firm is taking steps to address the situation and ensure that users are protected from potential vulnerabilities. It is crucial for organizations utilizing this plugin to act promptly and confirm their current version to mitigate risks associated with the compromised software.

Cybersecurity