As cited
Copy frozen at (site build).
breaches incidents
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack
Threat actors injected credential-stealing malware into Aqua Security's Trivy vulnerability scanner and related GitHub Actions on March 19, 2026. The attack, attributed to a group called TeamPCP, compromised the supply chain for a widely used open-source security tool. Organizations using Trivy need to audit for indicators of compromise and review credential exposure.
Why it matters: Security teams relying on Trivy for vulnerability scanning face immediate risk of credential theft and potential lateral movement; practitioners should check deployment logs, rotate credentials, and verify scanner integrity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack
Threat actors injected credential-stealing malware into Aqua Security's Trivy vulnerability scanner and related GitHub Actions on March 19, 2026. The attack, attributed to a group called TeamPCP, compromised the supply chain for a widely used open-source security tool. Organizations using Trivy need to audit for indicators of compromise and review credential exposure.
Why it matters: Security teams relying on Trivy for vulnerability scanning face immediate risk of credential theft and potential lateral movement; practitioners should check deployment logs, rotate credentials, and verify scanner integrity.
- Source published
- First seen by Cybersecurity Tracker