Malware & Tooling · Supply Chain

Trivy GitHub Actions Compromise Exposes CI/CD Secrets

TeamPCP used stolen credentials to compromise Aqua Security's Trivy repositories and their GitHub Actions automation. They force‑pushed version tags (76 of 77 trivy-action tags and all setup-trivy tags) and published an infected Trivy binary that harvests GitHub tokens, cloud credentials, SSH keys, and container/Kubernetes secrets.

11 sources · Mar 25

Timeline

Sources

Part of the PlainSec briefing for 2026-03-25

Every edition of this story: Trivy GitHub Actions Compromise Exposes CI/CD Secrets

More from today