44 Aqua Security repositories defaced after Trivy supply chain breach
ID: 791d2ea3-7e15-5406-a609-ce52ca6fd22a
STIX ID: report--791d2ea3-7e15-5406-a609-ce52ca6fd22a
Feed Name: Security Affairs
Threat Score
Malicious Trivy images published to Docker Hub delivered TeamPCP infostealer, and the same actor used stolen GitHub/CI credentials to compromise an Aqua Security internal GitHub org—automatically renaming and defacing 44 repositories within minutes; investigators provided IOCs and attribute the chain to TeamPCP’s automated supply‑chain and repository-level operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
