Malware & Tooling · Supply Chain
Trivy GitHub Actions Compromise Exposes CI/CD Secrets TeamPCP used stolen credentials to compromise Aqua Security's Trivy repositories and their GitHub Actions automation. They force‑pushed version tags (76 of 77 trivy-action tags and all setup-trivy tags) and published an infected Trivy binary that harvests GitHub tokens, cloud credentials, SSH keys, and container/Kubernetes secrets.
11 sources · Mar 25
Timeline Sources Mar 25 SecurityWeek
From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$.
original Mar 25 Microsoft Security Blog
Guidance for detecting, investigating, and defending against the Trivy supply chain compromise | Microsoft Security Blog
This analysis walks through the Trivy supply‑chain compromise, attacker techniques, and concrete steps security teams can take to detect and defend against similar attacks.
original Mar 25 The Hacker News
TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise
Malicious LiteLLM 1.82.7–1.82.8 via Trivy compromise deploys backdoor and steals credentials, enabling Kubernetes-wide persistence and lateral spread.
original Part of the PlainSec briefing for 2026-03-25
Every edition of this story: Trivy GitHub Actions Compromise Exposes CI/CD Secrets
More from today
Malware & Tooling · Supply Chain
Trivy GitHub Actions Compromise Exposes CI/CD Secrets TeamPCP used stolen credentials to compromise Aqua Security's Trivy repositories and their GitHub Actions automation. They force‑pushed version tags (76 of 77 trivy-action tags and all setup-trivy tags) and published an infected Trivy binary that harvests GitHub tokens, cloud credentials, SSH keys, and container/Kubernetes secrets.
11 sources · Mar 25
Timeline Sources Mar 25 SecurityWeek
From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$.
original Mar 25 Microsoft Security Blog
Guidance for detecting, investigating, and defending against the Trivy supply chain compromise | Microsoft Security Blog
This analysis walks through the Trivy supply‑chain compromise, attacker techniques, and concrete steps security teams can take to detect and defend against similar attacks.
original Mar 25 The Hacker News
TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise
Malicious LiteLLM 1.82.7–1.82.8 via Trivy compromise deploys backdoor and steals credentials, enabling Kubernetes-wide persistence and lateral spread.
original Part of the PlainSec briefing for 2026-03-25
Every edition of this story: Trivy GitHub Actions Compromise Exposes CI/CD Secrets
More from today