logo

Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper

ID: c97c9937-1163-5323-9f4e-bd81eccd5524

STIX ID: report--c97c9937-1163-5323-9f4e-bd81eccd5524

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-03-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers reported a supply-chain compromise of the Trivy container scanner and related GitHub Actions by the actor TeamPCP: malicious Trivy images (0.69.4–0.69.6) containing a TeamPCP infostealer were pushed to Docker Hub, a compromised Argon-DevOps-Mgt service account token was used to deface Aqua Security internal repositories, attackers leveraged stolen credentials to backdoor dozens of npm packages with a self-propagating CanisterWorm, and a separate payload functioning as a Kubernetes wiper selectively destroys Iranian clusters while installing backdoors elsewhere.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.