logo

Supply Chain Attacks Using Container Images

ID: 5a62b200-e619-525b-bce5-63a75be66387

STIX ID: report--5a62b200-e619-525b-bce5-63a75be66387

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2021-08-11

Date Updated: 2026-04-26

...
...

Team Nautilus (Aqua Security) identified five malicious Docker Hub images—some using typo‑squatting and misleading names—that execute a dao.py script or directly run the xmrig Monero miner (with provided MD5 hashes and pull counts), hijacking host resources for cryptocurrency mining; the report includes analysis, IOC details, and mitigation recommendations for supply‑chain and container registry security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.