logo

Investigating Two Variants of the Trivy Supply-Chain Compromise

ID: 1e0d9024-8342-587a-9f42-32067dbb2252

STIX ID: report--1e0d9024-8342-587a-9f42-32067dbb2252

Feed Name: Kudelski Security

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-07-22

...
...

In March 2026 the TeamPCP threat actor compromised the open-source Trivy scanner (GitHub Action and container image) to distribute credential-stealing payloads across multiple ecosystems; one variant exfiltrates secrets during CI runs, while the binary variant includes a persistent systemd-backed backdoor fetching second-stage payloads from an ICP-hosted C2. The report includes reverse-engineering details, CloudTrail tracing showing active AWS enumeration with stolen keys, S3 exposure concerns, attacker infrastructure (IPs, domains, MinIO), and a comprehensive set of IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.