Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Infostealer Attack via Docker Highlights Security Risks

Infostealer Attack via Docker Highlights Security Risks

Posted on March 23, 2026 By CWS

Cybersecurity experts have identified harmful artifacts distributed through Docker Hub, following a significant attack on Trivy, an open-source vulnerability scanner. This incident underscores the growing security threats in developer ecosystems.

Trivy’s Compromise and Its Implications

The last uncontaminated version of Trivy available on Docker Hub was 0.69.3. Subsequent malicious versions, 0.69.4 to 0.69.6, have been eliminated from the platform. These versions were uploaded without corresponding GitHub releases, indicating a breach. Security researcher Philipp Burckhardt noted that the compromised releases bore signs of the TeamPCP infostealer, previously detected in similar operations.

This breach is a consequence of a supply chain attack on Trivy, allowing attackers to exploit a compromised credential to introduce a credential-stealing trojan into the software. Additionally, two affiliated GitHub Actions, “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,” were targeted.

Further Repercussions and Worm Propagation

The attackers leveraged the stolen data to infiltrate numerous npm packages, deploying a self-replicating worm named CanisterWorm. This campaign is attributed to the threat group identified as TeamPCP. The OpenSourceMalware team reported that all 44 internal repositories of Aqua Security’s GitHub organization were compromised, each rebranded with a “tpcp-docs-” prefix and publicly exposed.

The repositories were altered en masse within a two-minute window on March 22, 2026, using a compromised “Argon-DevOps-Mgt” account. This account’s token, previously compromised, was instrumental in the attack, granting write access to both GitHub organizations involved.

Escalation and Broader Threats

TeamPCP continues to evolve its methods, now targeting cloud infrastructures with advanced capabilities. Their latest move involves deploying a novel wiper malware, spreading through SSH using stolen keys and exploiting exposed Docker APIs.

In a new escalation, TeamPCP has developed a payload targeting Kubernetes clusters, particularly in Iran. This wiper wipes Iranian nodes via a container named ‘kamikaze,’ while non-Iranian nodes are backdoored with CanisterWorm. Non-K8s Iranian systems face complete data destruction.

Preventive Measures and Industry Impact

Organizations must scrutinize their usage of Trivy, steering clear of the affected versions, and consider recent operations as potentially compromised. OpenSourceMalware emphasizes the long-lasting effects of supply chain attacks, highlighting the need for vigilance.

This incident highlights a critical irony: a cloud security firm falling victim to a cloud-native adversary. The ongoing attack serves as a stark reminder of the vulnerabilities within the security vendor ecosystem and the necessity for rigorous protective measures.

The Hacker News Tags:Aqua Security, CanisterWorm, cloud security, Cybersecurity, Docker, InfoStealer, Kubernetes, supply chain attack, TeamPCP, Trivy

Post navigation

Previous Post: New Stealth Malware Campaign Targets Key Sectors
Next Post: CanisterWorm Malware Targets npm, Compromises Developer Accounts

Related Posts

Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks The Hacker News
Researchers Reveal ReVault Attack Targeting Dell ControlVault3 Firmware in 100+ Laptop Models Researchers Reveal ReVault Attack Targeting Dell ControlVault3 Firmware in 100+ Laptop Models The Hacker News
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros The Hacker News
TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution The Hacker News
Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa The Hacker News
Think Your IdP or CASB Covers Shadow IT? These 5 Risks Prove Otherwise Think Your IdP or CASB Covers Shadow IT? These 5 Risks Prove Otherwise The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled
  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled
  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark