logo

Aqua Security’s Trivy Scanner Compromised in Supply Chain Attack

ID: 925c5cf0-c62c-56da-92c7-e5201e09afd0

STIX ID: report--925c5cf0-c62c-56da-92c7-e5201e09afd0

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-03-25

Date Updated: 2026-05-05

Author: Guru Baran

...
...

A supply-chain attack on Aqua Security's open-source Trivy scanner (late Feb–Mar 2026) leveraged a GitHub Actions misconfiguration and compromised credentials to force-push malicious commits and publish a backdoored Trivy binary (v0.69.4). The backdoor ran before legitimate scans to collect and exfiltrate CI/CD secrets (cloud creds, API tokens, SSH/K8s tokens, Docker config); remediation included credential rotation, removal of malicious releases, and deleting/repointing compromised tags, though the actor retained residual access and the campaign remains active. IOCs (domains, IPs, C2 endpoints, compromised binary and tags) are provided for hunting and containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.