Cloud Account Takeover After Trivy Supply-Chain Compromise
A compromised update to the Aqua Security Trivy vulnerability scanner delivered an API key that allowed attackers to take over an EU European Commission AWS account. This access enabled the theft of over 300GB of data from cloud infrastructure supporting public websites for the European Commission and affiliated EU entities. The attackers used the stolen key to create new access keys, perform reconnaissance, and pivot to other AWS accounts, demonstrating that the blast radius extends beyond local Trivy installations to any cloud environment trusting these credentials.
The incident unfolded over five days, with the API key compromised on March 19 and data exfiltration confirmed on March 24. This delay shows that attackers can maintain a multi-day dwell time in cloud environments after supply-chain compromises, making simple patching insufficient to contain the breach. Environments using the compromised Trivy build should be treated as fully breached across cloud services, not just as a