Trivy Security Tool Supply Chain Compromised by Threat Actor in March 2026
By
batch12
Slow-proofed and worth the wait. Worth its weight in flour.
Summary
A threat actor compromised the Trivy ecosystem supply chain in March 2026, using stolen credentials to publish malicious releases of Trivy v0.69.4 and later v0.69.5/v0.69.6 DockerHub images. The attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy to credential-stealing malware. The exposure window lasted approximately 3 hours for the initial v0.69.4 release and about 12 hours for the trivy-action repository. This supply chain attack targeted a popular open-source security scanning tool used for vulnerability detection in container images.
Key quotes
· 4 pulledOn March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action to credential-stealing malware, and replace all 7 tags in aquasecurity/setup-trivy with malicious commits.
On March 22, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.5 and v0.69.6 DockerHub images.
The exposure window lasted approximately 3 hours for the initial v0.69.4 release and about 12 hours for the trivy-action repository.
This supply chain attack targeted a popular open-source security scanning tool used for vulnerability detection in container images.
You might also wanna read
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
Trace-AI: Security Tool for Predicting and Preventing Supply-Chain Attacks in Open-Source Dependencies
Trace-AI is a security tool that predicts and prevents supply-chain attacks by analyzing open-source dependencies, registries, and maintaine
176 malicious npm packages used dependency confusion to target internal dependencies and steal credentials
Sonatype researchers uncovered a campaign involving 176 malicious npm packages using a dependency confusion attack strategy. Attackers publi
