All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Trivy Security Tool Supply Chain Compromised by Threat Actor in March 2026

By

batch12

2mo ago· 8 min readenCode

Summary

A threat actor compromised the Trivy ecosystem supply chain in March 2026, using stolen credentials to publish malicious releases of Trivy v0.69.4 and later v0.69.5/v0.69.6 DockerHub images. The attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy to credential-stealing malware. The exposure window lasted approximately 3 hours for the initial v0.69.4 release and about 12 hours for the trivy-action repository. This supply chain attack targeted a popular open-source security scanning tool used for vulnerability detection in container images.

Key quotes

· 4 pulled
On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action to credential-stealing malware, and replace all 7 tags in aquasecurity/setup-trivy with malicious commits.
On March 22, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.5 and v0.69.6 DockerHub images.
The exposure window lasted approximately 3 hours for the initial v0.69.4 release and about 12 hours for the trivy-action repository.
This supply chain attack targeted a popular open-source security scanning tool used for vulnerability detection in container images.
Snippet from the RSS feed
## Summary On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credent...

You might also wanna read