Malware & Tooling · Supply Chain

Attackers Backdoor Trivy GitHub Actions to Steal Secrets

Attackers force-pushed malicious commits to Aqua Security's Trivy repositories and official GitHub Actions. Backdoored releases were also pushed to Docker Hub and other container registries.

11 sources · Mar 27

Timeline

Sources

Part of the PlainSec briefing for 2026-03-22

Every edition of this story: Attackers Backdoor Trivy GitHub Actions to Steal Secrets