logo

Trivy Supply Chain Attack: What Happened and What You Need to Know

ID: 09f5e3bb-4b8d-5cdd-b0a9-dccb438f4e2f

STIX ID: report--09f5e3bb-4b8d-5cdd-b0a9-dccb438f4e2f

Feed Name: Aqua Security Blog

Threat Score
90/100

Date Published: 2026-03-21

Date Updated: 2026-04-26

...
...

**Open Source Security Advisory:** On March 19, 2026, attackers with retained access to Trivy's GitHub automation published a malicious Trivy binary (v0.69.4) and force-pushed multiple tags for aquasecurity/trivy-action and setup-trivy, causing CI/CD pipelines that used mutable tags to execute pre-scan malware that silently exfiltrated secrets (API tokens, cloud credentials, SSH keys, Kubernetes tokens, container registry credentials) to attacker-controlled infrastructure; the advisory includes timeline, affected components, IOCs, and immediate remediation and hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.