logo

Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub

ID: 3bf5b64f-a340-5f0f-b58e-3874be60584b

STIX ID: report--3bf5b64f-a340-5f0f-b58e-3874be60584b

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-03-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A supply-chain attack compromised the Trivy project: attackers gained access to GitHub Actions, pushed malicious Docker images (tags 0.69.4–0.69.6) to Docker Hub containing the TeamPCP infostealer, exfiltration artifacts, and a typosquatted C2 domain. Organizations using affected tags in CI/CD pipelines should assume compromise, rotate secrets, verify image digests, and roll back to the last known clean release (0.69.3).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.