logo

Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack

ID: 6890ad48-4025-59f2-9f07-9a96552b34a1

STIX ID: report--6890ad48-4025-59f2-9f07-9a96552b34a1

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2026-03-20

Date Updated: 2026-05-01

...
...

On March 19, 2026, threat actors (self-identifying as TeamPCP) performed a multi-component supply-chain compromise of Aqua Security's Trivy: malicious commits and forced tag updates injected credential-stealing code into trivy-action, setup-trivy, and the Trivy v0.69.4 binary, exfiltrating secrets via a typosquatted domain and Cloudflare Tunnel, publishing backdoored artifacts to multiple registries, and creating fallback exfiltration via a tpcp-docs GitHub repo; the report provides technical behavior, IOCs, and remediation steps including artifact removal and action pinning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.