Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Supply Chain Breach Targets Aqua’s Trivy Vulnerability Tool

Supply Chain Breach Targets Aqua’s Trivy Vulnerability Tool

Posted on March 23, 2026 By CWS

Aqua Security’s Trivy vulnerability scanner fell victim to a supply chain attack beginning in late February, causing significant concern within the cybersecurity community. The attack was officially confirmed on March 1 when Trivy’s GitHub repository was discovered to have been compromised due to a GitHub Actions workflow issue. This incident led to the deletion of some releases and the introduction of malicious versions of its VS Code extensions to the Open VSIX marketplace.

Details of the GitHub Repository Compromise

The breach was part of a broader automated campaign targeting multiple open source repositories through GitHub Actions workflows. This resulted in the injection of harmful natural-language prompts into two corrupt versions of Trivy’s VS Code extension. The attackers exploited credentials exfiltrated during the initial breach to orchestrate a subsequent supply chain attack affecting not only the Trivy package but also trivy-action and setup-trivy, as confirmed in a March 21 advisory.

According to Trivy’s maintainers, although credentials were rotated following the initial disclosure, not all were revoked simultaneously, allowing attackers to leverage a valid token to extract newly rotated secrets during a brief window. This enabled them to distribute a malicious Trivy release (version v0.69.4) through standard channels such as GitHub Container Registry, Amazon ECR Public, and Docker Hub.

Impact and Technical Analysis of the Attack

The attackers further manipulated 76 out of 77 trivy-action version tags, pushing them to malicious commits that included an information stealer designed to dump the Runner.Worker process memory and extract all secrets. The sophisticated malware encrypted the harvested data, transmitting it to a remote server. In cases of exfiltration failure, the malware created a public GitHub repository to upload the data.

Moreover, they targeted the setup-trivy releases by force-pushing all tags to malicious commits, utilizing the same infostealer. Technical insights into the attack and malware were provided by security firms Socket and Wiz. Despite these challenges, Aqua Security ensured that its commercial products using Trivy remained unaffected due to a controlled integration process that lags behind the open source version.

Response and Future Outlook

Aqua Security noted ongoing and evolving threats, with unauthorized changes and repository tampering detected as recently as March 22. They continue to focus on identifying and securing all potential access paths. In response, Trivy’s maintainers released clean versions of Trivy and its associated tools, urging users to rotate all credentials if compromised versions were used in their environments.

The attack has been linked to the threat actor TeamPCP, which has expanded its operations by targeting the NPM ecosystem with CanisterWorm malware. The group is known for financial motivations, emerging in late 2025, and targeting cloud-native infrastructures. This incident highlights the growing importance of securing the software supply chain to prevent similar attacks in the future.

Security Week News Tags:Aqua Security, CanisterWorm, Cybersecurity, GitHub actions, Malware, Open Source, supply chain attack, TeamPCP, Trivy, vulnerability scanner

Post navigation

Previous Post: Unveiling Eight Attack Vectors in AWS Bedrock
Next Post: Trivy Supply Chain Attack Expands to Docker Hub

Related Posts

Suspected DoppelPaymer Ransomware Group Member Arrested Suspected DoppelPaymer Ransomware Group Member Arrested Security Week News
China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear Security Week News
Lumia Security Raises  Million for AI Security and Governance Lumia Security Raises $18 Million for AI Security and Governance Security Week News
Data Breach at Conduent Exposes Volvo Group Employees Data Breach at Conduent Exposes Volvo Group Employees Security Week News
Hackers Start Exploiting Critical Cisco ISE Vulnerabilities Hackers Start Exploiting Critical Cisco ISE Vulnerabilities Security Week News
CPAP Medical Data Breach Impacts 90,000 People CPAP Medical Data Breach Impacts 90,000 People Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Oblivion RAT Exploits Fake Updates for Android Espionage
  • M-Trends 2026: Rapid Change in Cyber Threat Dynamics
  • Supply Chain Attacks Surge Amid New Malware Techniques
  • Trivy Supply Chain Attack Expands to Docker Hub
  • Supply Chain Breach Targets Aqua’s Trivy Vulnerability Tool

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Oblivion RAT Exploits Fake Updates for Android Espionage
  • M-Trends 2026: Rapid Change in Cyber Threat Dynamics
  • Supply Chain Attacks Surge Amid New Malware Techniques
  • Trivy Supply Chain Attack Expands to Docker Hub
  • Supply Chain Breach Targets Aqua’s Trivy Vulnerability Tool

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark