Attori malintenzionati backdoorano Trivy Actions e rubano segreti CI/CD
Gli attori malintenzionati hanno compromesso Trivy e le GitHub Actions ufficiali di Aqua Security. Il payload eseguito nei runner GitHub Actions ruba token GitHub/PAT, credenziali cloud, SSH key, Docker e Kubernetes token e li invia a server controllati dagli attaccanti.
Hackers Supply Chain Attack Moves From npm to PyPI as Trivy Breach Extends into LiteLLM Package
Analysis of the TeamPCP supply chain attack linking Trivy, GitHub Actions, npm, and LiteLLM, including how the credential stealer works and what defenders should do next.
Guidance for detecting, investigating, and defending against the Trivy supply chain compromise | Microsoft Security Blog
This analysis walks through the Trivy supply‑chain compromise, attacker techniques, and concrete steps security teams can take to detect and defend against similar attacks.