Checkmarx says a compromised version of its Jenkins Application Security Testing (AST) plugin was published to the Jenkins Marketplace as part of a supply-chain attack. Multiple outlets report that the malicious package was available for download for a period before Checkmarx’s warning over the weekend. Checkmarx’s statement directs users to verify the version they are running and to ensure they use a known safe release. Specifically, it says users should be on version 2.0.13-829.vc72453fa_1c16 or earlier than the compromised upload window, referencing a publication date of December 17, 2025 or before.

Bleeping Computer reports the rogue package is associated with “infostealer,” indicating the plugin contained code intended to capture information. SecurityWeek also describes the incident as a malicious version of the plugin being uploaded to the Jenkins Marketplace late last week. The Hacker News similarly focuses on Checkmarx’s confirmation of the modified Jenkins AST plugin and the need for users to check their installed version. Checkmarx continues to provide guidance on remediation, and affected users are urged to review their plugin installations and update accordingly.