logo

Trivy supply-chain attack spreads to Docker, GitHub repos

ID: 48d13878-498a-5bd4-84ba-f418417fe447

STIX ID: report--48d13878-498a-5bd4-84ba-f418417fe447

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-03-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

TeamPCP compromised Aqua Security's GitHub organization and CI environment to inject credential‑harvesting malware into Trivy builds, pushed malicious Docker image tags to Docker Hub, and tampered with multiple repositories; researchers provided IOCs and Aqua engaged incident responders while warning that Docker tags are not immutable and that service account PATs in CI runners enabled the compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.