Supply Chain Attacks Using Container Images
ID: 5a62b200-e619-525b-bce5-63a75be66387
STIX ID: report--5a62b200-e619-525b-bce5-63a75be66387
Feed Name: Aqua Security Blog
Threat Score
Team Nautilus (Aqua Security) identified five malicious Docker Hub images—some using typo‑squatting and misleading names—that execute a dao.py script or directly run the xmrig Monero miner (with provided MD5 hashes and pull counts), hijacking host resources for cryptocurrency mining; the report includes analysis, IOC details, and mitigation recommendations for supply‑chain and container registry security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
