Official CheckMarx Jenkins package compromised with infostealer
… A company spokesperson confirmed to BleepingComputer that the threat actor obtained credentials to the repositories from the Trivy supply-chain attack in March. …
Tracked topic
Trivy is an open source vulnerability scanner for container images, files, and code that detects known security issues in software dependencies.