A rogue Checkmarx-related plugin release on the Jenkins Marketplace shows how quickly CI/CD trust can become an attack surface.
Checkmarx confirmed a modified version of its Jenkins AST plugin was published through the Jenkins distribution path, a reminder that software trust chains are as valuable to attackers as the code they deliver.