logo

44 Aqua Security repositories defaced after Trivy supply chain breach

ID: aa4357a2-0066-52e3-9b91-e7e8ed4a27ab

STIX ID: report--aa4357a2-0066-52e3-9b91-e7e8ed4a27ab

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers report that TeamPCP compromised Trivy GitHub Actions to distribute malicious Docker images (infostealer) and stole a long-lived service account token which they used to automatically rename and deface all 44 repositories in an Aqua Security internal GitHub organization within minutes, exposing internal code, tools, and likely secrets; IOCs were published by investigators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.