logo

Trivy Tag Compromise Supply Chain Attack

ID: a3be69bf-35f3-5e7c-af8f-6ddceaab171d

STIX ID: report--a3be69bf-35f3-5e7c-af8f-6ddceaab171d

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2026-03-23

Date Updated: 2026-07-22

...
...

Trivy's release process was compromised when attackers reassigned the v0.69.4 Git tag to malicious commits and published a release containing binaries that collect environment variables, configuration data, and CI secrets and exfiltrate them to attacker infrastructure; this active supply-chain attack can propagate broadly via automated CI/CD and developer workflows, and recommended mitigations include avoiding unverified tags, pinning commit SHAs, enforcing tag/release protections, rotating exposed secrets, and validating releases via checksums or cryptographic signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.