logo

Microsoft Unveils New Guidance to Detect and Defend Against Trivy Supply Chain Attack

ID: 9af5c775-ee8c-5249-9157-d8ae07442a3b

STIX ID: report--9af5c775-ee8c-5249-9157-d8ae07442a3b

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Divya

...
...

**Supply-chain compromise of Trivy by TeamPCP:** TeamPCP abused mutable Git tags and forged commit identities to inject a Python-based credential-stealing payload into Trivy releases and GitHub Action tags, publishing infected binaries and container images that exfiltrate cloud credentials, Kubernetes secrets, application tokens, and other infrastructure secrets while letting legitimate scans complete to hide activity; mitigations include updating to verified safe versions, pinning actions to commit SHAs, minimizing GITHUB_TOKEN scope, and using secret managers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.