Trivy Supply Chain Attack: What Happened and What You Need to Know
ID: 09f5e3bb-4b8d-5cdd-b0a9-dccb438f4e2f
STIX ID: report--09f5e3bb-4b8d-5cdd-b0a9-dccb438f4e2f
Feed Name: Aqua Security Blog
**Open Source Security Advisory:** On March 19, 2026, attackers with retained access to Trivy's GitHub automation published a malicious Trivy binary (v0.69.4) and force-pushed multiple tags for aquasecurity/trivy-action and setup-trivy, causing CI/CD pipelines that used mutable tags to execute pre-scan malware that silently exfiltrated secrets (API tokens, cloud credentials, SSH keys, Kubernetes tokens, container registry credentials) to attacker-controlled infrastructure; the advisory includes timeline, affected components, IOCs, and immediate remediation and hardening guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
