Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. A popular open-source vulnerability scanner (Trivy) was compromised last week in a supply chain attack

A popular open-source vulnerability scanner (Trivy) was compromised last week in a supply chain attack

Scheduled Pinned Locked Moved Uncategorized
2 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • campuscodi@mastodon.socialC This user is from outside of this forum
    campuscodi@mastodon.socialC This user is from outside of this forum
    campuscodi@mastodon.social
    wrote last edited by
    #1

    A popular open-source vulnerability scanner (Trivy) was compromised last week in a supply chain attack

    Link Preview Image
    Update: Ongoing Investigation and Continued Remediation

    Open Source Security Advisory Update: Wednesday, March 25, 2026 Boston, MA 12:30 AM ET  Our response has progressed into the remediation and documentation phase. With the core investigation and immediate containment actions largely complete, our focus is now on consolidating findings and communicating them clearly to customers and stakeholders.  Working closely with Sygnia, we are developing formal documentation that includes the confirmed …

    favicon

    Aqua (www.aquasec.com)

    Link Preview Image
    TeamPCP deploys CanisterWorm on NPM following Trivy compromise

    TeamPCP deploys CanisterWorm on NPM following Trivy compromise

    favicon

    (www.aikido.dev)

    Link Preview Image
    Trivy Security incident 2026-03-19 · aquasecurity/trivy · Discussion #10425

    Trivy Security incident 2026-03-19

    favicon

    GitHub (github.com)

    Link Preview Image
    Trivy Under Attack Again: Widespread GitHub Actions Tag Comp...

    Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.

    favicon

    Socket (socket.dev)

    Link Preview Image
    Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity

    On March 19, 2026, trivy — a widely used open source vulnerability scanner maintained by Aqua Security — experienced a second security incident. Three weeks after the hackerbot-claw incident on February 28 that resulted in a repository takeover, a new compromised release (v0.69.4) was published to the trivy repository. The original incident disclosure discussion (#10265) was also deleted during this period, and version tags on the aquasecurity/setup-trivy GitHub Action were removed. Trivy maintainers deleted the v0.69.4 tag and Homebrew downgraded to v0.69.3. The following is a factual account of what we observed through public GitHub data.

    favicon

    (www.stepsecurity.io)

    Link Preview Image
    Trivy Compromised by "TeamPCP" | Wiz Blog

    Breaking down the March 2026 Trivy supply chain attack. TeamPCP compromised trivy + trivy-action & setup-trivy GitHub Actions, deploying credential stealers.

    favicon

    wiz.io (www.wiz.io)

    Link Preview Image
    From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise

    CrowdStrike discusses how this activity was discovered, how the attack works, what the payload does, and how to defend.

    favicon

    CrowdStrike.com (www.crowdstrike.com)

    bontchev@infosec.exchangeB 1 Reply Last reply
    0
    • campuscodi@mastodon.socialC campuscodi@mastodon.social

      A popular open-source vulnerability scanner (Trivy) was compromised last week in a supply chain attack

      Link Preview Image
      Update: Ongoing Investigation and Continued Remediation

      Open Source Security Advisory Update: Wednesday, March 25, 2026 Boston, MA 12:30 AM ET  Our response has progressed into the remediation and documentation phase. With the core investigation and immediate containment actions largely complete, our focus is now on consolidating findings and communicating them clearly to customers and stakeholders.  Working closely with Sygnia, we are developing formal documentation that includes the confirmed …

      favicon

      Aqua (www.aquasec.com)

      Link Preview Image
      TeamPCP deploys CanisterWorm on NPM following Trivy compromise

      TeamPCP deploys CanisterWorm on NPM following Trivy compromise

      favicon

      (www.aikido.dev)

      Link Preview Image
      Trivy Security incident 2026-03-19 · aquasecurity/trivy · Discussion #10425

      Trivy Security incident 2026-03-19

      favicon

      GitHub (github.com)

      Link Preview Image
      Trivy Under Attack Again: Widespread GitHub Actions Tag Comp...

      Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.

      favicon

      Socket (socket.dev)

      Link Preview Image
      Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity

      On March 19, 2026, trivy — a widely used open source vulnerability scanner maintained by Aqua Security — experienced a second security incident. Three weeks after the hackerbot-claw incident on February 28 that resulted in a repository takeover, a new compromised release (v0.69.4) was published to the trivy repository. The original incident disclosure discussion (#10265) was also deleted during this period, and version tags on the aquasecurity/setup-trivy GitHub Action were removed. Trivy maintainers deleted the v0.69.4 tag and Homebrew downgraded to v0.69.3. The following is a factual account of what we observed through public GitHub data.

      favicon

      (www.stepsecurity.io)

      Link Preview Image
      Trivy Compromised by "TeamPCP" | Wiz Blog

      Breaking down the March 2026 Trivy supply chain attack. TeamPCP compromised trivy + trivy-action & setup-trivy GitHub Actions, deploying credential stealers.

      favicon

      wiz.io (www.wiz.io)

      Link Preview Image
      From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise

      CrowdStrike discusses how this activity was discovered, how the attack works, what the payload does, and how to defend.

      favicon

      CrowdStrike.com (www.crowdstrike.com)

      bontchev@infosec.exchangeB This user is from outside of this forum
      bontchev@infosec.exchangeB This user is from outside of this forum
      bontchev@infosec.exchange
      wrote last edited by
      #2

      @campuscodi The vulnerability scanner was vulnerable. 🤣 Doctor, heal thyself.

      1 Reply Last reply
      1
      0
      • R relay@relay.infosec.exchange shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups