Malware & Tooling · Supply Chain
Attackers force-pushed malicious commits to Aqua Security's Trivy repositories and official GitHub Actions. Backdoored releases were also pushed to Docker Hub and other container registries.
11 sources · Mar 27
Semgrep Blog
Hackers Supply Chain Attack Moves From npm to PyPI as Trivy Breach Extends into LiteLLM Package
Analysis of the TeamPCP supply chain attack linking Trivy, GitHub Actions, npm, and LiteLLM, including how the credential stealer works and what defenders should do next.
originalSecurityWeek
From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$.
originalMicrosoft Security Blog
Guidance for detecting, investigating, and defending against the Trivy supply chain compromise | Microsoft Security Blog
This analysis walks through the Trivy supply‑chain compromise, attacker techniques, and concrete steps security teams can take to detect and defend against similar attacks.
originalPart of the PlainSec briefing for 2026-03-22
Every edition of this story: Attackers Backdoor Trivy GitHub Actions to Steal Secrets