Malware · 174 days ago

Trivy GitHub Actions Compromise Exposes CI/CD Secrets

Aqua Security's Trivy GitHub Actions repositories were force-pushed and 75 tags replaced with malicious versions. The injected payload ran in GitHub Actions runners and exfiltrated CI/CD and developer secrets.

Timeline

Sources

11 sources covering this story

Part of the PlainSec briefing for 2026-03-27

Editions

Related stories