logo

Trivy Supply Chain Attack Spreads via Compromised Docker Hub Images

ID: 78ffee6f-e934-54b5-a058-2de06647c7c3

STIX ID: report--78ffee6f-e934-54b5-a058-2de06647c7c3

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A supply-chain attack has compromised Trivy Docker images (notably tags 0.69.5 and 0.69.6) on Docker Hub; analysis links these images to the TeamPCP infostealer (exfiltration artifacts, typosquatted C2 domain, and references to a fallback GitHub repo). Version 0.69.3 is the last verified clean release, attackers may have published unauthorized releases and possibly accessed Aqua Security's GitHub organization, and organizations are advised to audit CI/CD pipelines, avoid affected versions, and revoke credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.