ClosedMedium impactAI Generated

Checkmarx Jenkins AST Plugin Compromised with Infostealer – May 2026

Occurred 11 May 2026·Detected 12 May 2026·
🇺🇸 Global – originating via the Jenkins Marketplace; Checkmarx is a US/Israel-headquartered vendor1 reportEnded 29 May 2026
CyberPropertyCyberCasualty & Liability

Checkmarx issued a warning over the weekend of 11 May 2026 that a rogue, malicious version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. The compromised package contained infostealer malware designed to exfiltrate sensitive data from developer and CI/CD environments. The incident represents a software supply chain attack targeting users of the widely used Jenkins continuous integration platform. Checkmarx advised affected users to remove the rogue plugin immediately.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. The compromise of an official plugin on a widely used marketplace (Jenkins) has significant potential reach across enterprise DevOps environments globally, with risk of credential theft, data exfiltration, and downstream pipeline compromise. However, the full scope of affected organisations is not yet confirmed.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

1 active match

  • TRIA Certified Areas
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

🇬🇱 Global🇺🇸 United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts