Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub
ID: 3bf5b64f-a340-5f0f-b58e-3874be60584b
STIX ID: report--3bf5b64f-a340-5f0f-b58e-3874be60584b
Feed Name: cybersecurityNews.com
Threat Score
A supply-chain attack compromised the Trivy project: attackers gained access to GitHub Actions, pushed malicious Docker images (tags 0.69.4–0.69.6) to Docker Hub containing the TeamPCP infostealer, exfiltration artifacts, and a typosquatted C2 domain. Organizations using affected tags in CI/CD pipelines should assume compromise, rotate secrets, verify image digests, and roll back to the last known clean release (0.69.3).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
