Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Infostealer Attack via Docker Highlights Security Risks

Infostealer Attack via Docker Highlights Security Risks

Posted on March 23, 2026 By CWS

Cybersecurity experts have identified harmful artifacts distributed through Docker Hub, following a significant attack on Trivy, an open-source vulnerability scanner. This incident underscores the growing security threats in developer ecosystems.

Trivy’s Compromise and Its Implications

The last uncontaminated version of Trivy available on Docker Hub was 0.69.3. Subsequent malicious versions, 0.69.4 to 0.69.6, have been eliminated from the platform. These versions were uploaded without corresponding GitHub releases, indicating a breach. Security researcher Philipp Burckhardt noted that the compromised releases bore signs of the TeamPCP infostealer, previously detected in similar operations.

This breach is a consequence of a supply chain attack on Trivy, allowing attackers to exploit a compromised credential to introduce a credential-stealing trojan into the software. Additionally, two affiliated GitHub Actions, “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,” were targeted.

Further Repercussions and Worm Propagation

The attackers leveraged the stolen data to infiltrate numerous npm packages, deploying a self-replicating worm named CanisterWorm. This campaign is attributed to the threat group identified as TeamPCP. The OpenSourceMalware team reported that all 44 internal repositories of Aqua Security’s GitHub organization were compromised, each rebranded with a “tpcp-docs-” prefix and publicly exposed.

The repositories were altered en masse within a two-minute window on March 22, 2026, using a compromised “Argon-DevOps-Mgt” account. This account’s token, previously compromised, was instrumental in the attack, granting write access to both GitHub organizations involved.

Escalation and Broader Threats

TeamPCP continues to evolve its methods, now targeting cloud infrastructures with advanced capabilities. Their latest move involves deploying a novel wiper malware, spreading through SSH using stolen keys and exploiting exposed Docker APIs.

In a new escalation, TeamPCP has developed a payload targeting Kubernetes clusters, particularly in Iran. This wiper wipes Iranian nodes via a container named ‘kamikaze,’ while non-Iranian nodes are backdoored with CanisterWorm. Non-K8s Iranian systems face complete data destruction.

Preventive Measures and Industry Impact

Organizations must scrutinize their usage of Trivy, steering clear of the affected versions, and consider recent operations as potentially compromised. OpenSourceMalware emphasizes the long-lasting effects of supply chain attacks, highlighting the need for vigilance.

This incident highlights a critical irony: a cloud security firm falling victim to a cloud-native adversary. The ongoing attack serves as a stark reminder of the vulnerabilities within the security vendor ecosystem and the necessity for rigorous protective measures.

The Hacker News Tags:Aqua Security, CanisterWorm, cloud security, Cybersecurity, Docker, InfoStealer, Kubernetes, supply chain attack, TeamPCP, Trivy

Post navigation

Previous Post: New Stealth Malware Campaign Targets Key Sectors
Next Post: CanisterWorm Malware Targets npm, Compromises Developer Accounts

Related Posts

GitHub Vulnerability in Codespaces Exposes GITHUB_TOKEN GitHub Vulnerability in Codespaces Exposes GITHUB_TOKEN The Hacker News
New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers The Hacker News
Security Flaw in Vertex AI Risks Google Cloud Data Security Flaw in Vertex AI Risks Google Cloud Data The Hacker News
AI-Powered Typosquatting Threatens Supply Chains AI-Powered Typosquatting Threatens Supply Chains The Hacker News
SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny The Hacker News
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Levi Strauss Faces Cyber Intrusion via Social Engineering
  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Levi Strauss Faces Cyber Intrusion via Social Engineering
  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark