logo

44 Aqua Security repositories defaced after Trivy supply chain breach

ID: 791d2ea3-7e15-5406-a609-ce52ca6fd22a

STIX ID: report--791d2ea3-7e15-5406-a609-ce52ca6fd22a

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Malicious Trivy images published to Docker Hub delivered TeamPCP infostealer, and the same actor used stolen GitHub/CI credentials to compromise an Aqua Security internal GitHub org—automatically renaming and defacing 44 repositories within minutes; investigators provided IOCs and attribute the chain to TeamPCP’s automated supply‑chain and repository-level operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.