logo

Trivy supply-chain

Multiple security reports describe a March 19–22, 2026 supply‑chain compromise of Aqua Security’s Trivy (attributed to “TeamPCP”) in which attackers abused GitHub Actions and mutable tags to publish backdoored binaries and Docker images that harvested and exfiltrated CI/cloud/Kubernetes credentials, with IOCs and remediation guidance (pin to SHAs, rotate secrets, verify image digests) provided.

List of posts related to this topic

Post TitleDate PublishedDescribes IncidentFeed
AppSec as attacker: Inside Trivy–LiteLLM 2026-03-27TrueReversingLabs Blog
Not Subscribed
Microsoft Unveils New Guidance to Detect and Defend Against Trivy Supply Chain Attack2026-03-26TrueGBHackers
Not Subscribed
Aqua Security’s Trivy Scanner Compromised in Supply Chain Attack2026-03-25TruecybersecurityNews.com
Not Subscribed
Guidance for detecting, investigating, and defending against the Trivy supply chain compromise2026-03-25TrueMicrosoft Security
Not Subscribed
1K+ cloud environments infected following Trivy supply chain attack2026-03-24TrueThe Register (Security)
Not Subscribed
The Trivy Supply Chain Compromise: What Happened and Playbooks to Respond2026-03-24TrueSecurity Boulevard
Not Subscribed
Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack2026-03-24TrueCyberScoop
Not Subscribed
Trivy Supply Chain Attack Targets CI/CD Secrets2026-03-23TrueDark Reading
Not Subscribed
Trivy supply-chain attack spreads to Docker, GitHub repos2026-03-23TrueBleeping Computer
Not Subscribed
Trivy Supply Chain Attack Expands With New Compromised Docker Images2026-03-23TrueInfosecurity Magazine (News)
Not Subscribed
44 Aqua Security repositories defaced after Trivy supply chain breach2026-03-23TrueSecurity Affairs
Not Subscribed
44 Aqua Security repositories defaced after Trivy supply chain breach2026-03-23TrueSecurity Affairs
Not Subscribed
Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub2026-03-23TruecybersecurityNews.com
Not Subscribed
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper2026-03-23TrueThe Hacker News
Not Subscribed
Trivy Supply Chain Attack Spreads via Compromised Docker Hub Images2026-03-23TrueGBHackers
Not Subscribed
Update: Ongoing Investigation and Additional Activity2026-03-23TrueAqua Security Blog
Not Subscribed
TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions2026-03-23TrueSysdig Blog
Not Subscribed
TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions2026-03-23TrueSysdig Blog
Not Subscribed
Trivy vulnerability scanner breach pushed infostealer via GitHub Actions2026-03-21TrueBleeping Computer
Not Subscribed
Trivy Supply Chain Attack: What Happened and What You Need to Know2026-03-21TrueAqua Security Blog
Not Subscribed
Trivy Vulnerability Scanner Compromised to Inject Malicious Scripts That Steal Credentials2026-03-21TrueGBHackers
Not Subscribed
Hackers Compromise Trivy Scanner to Inject malicious Scripts and Steal Login Credentials2026-03-21TruecybersecurityNews.com
Not Subscribed
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets2026-03-20TrueThe Hacker News
Not Subscribed
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack2026-03-20TrueWiz Blog
Not Subscribed
From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise2026-03-20TrueCrowdstrike Blog
Not Subscribed

1–25 of 25