Malicious version of Checkmarx Jenkins plugin published

Application security firm Checkmarx has again been hit by a supply chain attack. This time a malicious version of the company's Jenkins AST plugin was published to the Jenkins Marketplace. The window was relatively short, roughly 31 hours, but the incident follows similar attacks on the company in March and April this year. The malware was built to steal information from software development environments.

What this means for your organisation

A software security tool has, by design, deep access to source code and the build platform. When that tool becomes the way in, little of the defence at that layer remains. Thirty-one hours is ample time to harvest secrets from a build server that runs around the clock. The fact that the same vendor has been hit three times in a few months is itself information worth carrying into your supplier assessment.

Berigo recommends

  • Check which Jenkins plugin versions were installed or updated during the affected period.
  • Rotate every secret the Jenkins installation has had access to, without waiting for confirmed compromise.
  • Turn off automatic plugin updates on the build platform and introduce a short quarantine for new versions.
  • Ask the vendor to explain in writing why three incidents have occurred in short order, and what has changed.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch