Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack

On March 19, 2026, threat actors attributed to "TeamPCP" injected credential-stealing malware into Aqua Security's Trivy scanner and related GitHub Actions. The compromise affected the supply chain of a widely-used container security tool, potentially exposing credentials and secrets in CI/CD environments.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Trivy scanner users and GitHub Actions workflows; potential exposure of credentials and secrets in CI/CD pipelines
Ecosystems
Attack vectors
Threat actor
Affected entities
  • TrivyAqua Security's container vulnerability scanner
  • Trivy GitHub ActionsRelated GitHub Actions for Trivy

On March 19, 2026, threat actors injected credential-stealing malware into Aqua Security's Trivy scanner and its associated GitHub Actions. The attack was attributed to a group known as "TeamPCP."

Trivy is a widely-used open-source vulnerability scanner for containers and other artifacts. The compromise of this tool represents a significant supply chain attack, as it could affect numerous organizations relying on Trivy for security scanning in their CI/CD pipelines.

The injected malware was designed to steal credentials, posing a risk to users who executed the compromised versions. Organizations using Trivy or its GitHub Actions should audit their environments for potential credential exposure and take immediate remediation steps.

The incident demonstrates the risk of supply chain attacks targeting popular open-source security tools, where a single compromise can cascade across many downstream users and organizations.

Remediation

  • Immediately audit CI/CD logs and environment variables for credential exposure
  • Rotate all credentials and secrets that may have been exposed through Trivy execution
  • Update Trivy to a patched version confirmed to be free of malware
  • Review GitHub Actions workflows using Trivy and verify their integrity
  • Implement additional credential scanning and secret management controls in CI/CD pipelines
  • Monitor for unauthorized access using credentials that may have been compromised

Sources

  1. Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack · Wiz

Cite this entry

"Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed March 19, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/trivy-compromised-everything-you-need-to-know-about-the-latest-supply-chain-atta-103yjm

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in gantt-for-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-sdk-app (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit