Widely used Trivy scanner compromised in ongoing supply-chain attack

Widely used Trivy scanner compromised in ongoing supply-chain attack

A significant security breach has affected Aqua Security's Trivy vulnerability scanner, impacting nearly all versions in a supply chain attack that poses serious risks for developers and their organizations. The incident was confirmed by Itay Shakury, a maintainer of Trivy, following a series of discussions on the matter that were later deleted by the attackers. The attack unfolded in the early hours of Thursday, during which hackers exploited stolen credentials to execute a forced push. This action resulted in the alteration of nearly all trivy-action tags and seven setup-trivy tags, replacing them with malicious dependencies. A forced push circumvents the standard safeguards in Git, allowing for the overwriting of existing commits, which creates an avenue for potential exploitation. Trivy is instrumental for developers, being utilized to identify vulnerabilities and detect hardcoded authentication secrets throughout software development pipelines. With over 33,200 stars on GitHub, its popularity underscores its critical role in modern software development. In a warning to users, Shakury advised that if there’s a chance of using a compromised version, all pipeline secrets should be considered at risk and should be rotated immediately. Security firms Socket and Wiz reported that the malware linked to 75 compromised trivy-action tags is designed to thoroughly search development environments for sensitive information such as GitHub tokens, cloud credentials, SSH keys, and Kubernetes tokens. Once these secrets are detected, the malware encrypts the data before sending it to servers controlled by the attackers. Consequently, any CI/CD pipeline that utilizes software referencing the compromised version tags will execute malicious code when a Trivy scan is performed. The spoofed version tags notably include widely used releases like @0.34.2, @0.33, and @0.18.0, with only version @0.35.0 remaining unaffected.

Sources : Ars Technica

Published On : Mar 20, 2026, 20:55

AI
The Shift in Human Cognition: Embracing AI as a Collaborative Tool

As technology continues to evolve, a notable shift is occurring in the relationship between humans and artificial intell...

Business Insider | Jul 25, 2026, 09:50
The Shift in Human Cognition: Embracing AI as a Collaborative Tool
AI
Hugging Face CEO Calls for Action Following AI Security Breach

In a dramatic turn of events within the AI landscape, Hugging Face faced a significant security breach involving an AI a...

Business Insider | Jul 25, 2026, 20:30
Hugging Face CEO Calls for Action Following AI Security Breach
AI
The Rise of AI Distillation: A Controversial Technique Sparks Debate in Tech and Government

In recent discussions, a once-obscure topic in artificial intelligence has surged to the forefront of debates among tech...

CNBC | Jul 25, 2026, 12:15
The Rise of AI Distillation: A Controversial Technique Sparks Debate in Tech and Government
Streaming
Kalshi Challenges Netflix Over Controversial Documentary Trailer

Kalshi, the prediction market platform, has taken significant legal steps against Netflix, sending a cease-and-desist le...

TechCrunch | Jul 25, 2026, 17:10
Kalshi Challenges Netflix Over Controversial Documentary Trailer
Startups
AI Transformations Lead to Major Job Cuts at Tech Giants

Monday.com, the innovative work management platform based in Tel Aviv, has recently announced significant layoffs, attri...

TechCrunch | Jul 26, 2026, 01:45
AI Transformations Lead to Major Job Cuts at Tech Giants
View All News