Malware & Tooling · Supply Chain

Trivy GitHub Actions Compromise Exposes CI/CD Secrets

Aqua Security's Trivy GitHub Actions repositories were force-pushed and 75 tags replaced with malicious versions. The injected payload ran in GitHub Actions runners and exfiltrated CI/CD and developer secrets.

11 sources · Mar 25

Timeline

Sources

Part of the PlainSec briefing for 2026-03-27

Every edition of this story: Trivy GitHub Actions Compromise Exposes CI/CD Secrets

More from today