logo

Trivy Supply Chain Attack Targets CI/CD Secrets

ID: 8c5b908e-64c5-50e4-a925-61a0deb38e08

STIX ID: report--8c5b908e-64c5-50e4-a925-61a0deb38e08

Feed Name: Dark Reading

Threat Score
92/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Jai Vijayan

...
...

A supply-chain attack against the Trivy open-source scanner compromised its GitHub Actions and release pipeline in February–March, allowing an attacker to force-push malicious code to trivy-action and setup-trivy releases and publish compromised Trivy Docker images and a trojanized Trivy version. The deployed credential-harvesting infostealer scans CI/CD environments for SSH keys, AWS/GCP/Azure credentials, Kubernetes tokens, Docker and environment files, and exfiltrates data using AES-256-CBC with RSA-4096 or by uploading to public GitHub repos; Aqua Security recommends rotating secrets, auditing workflows, removing affected versions, and searching for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.