{"id":152987,"date":"2026-03-24T22:33:42","date_gmt":"2026-03-24T20:33:42","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=152987"},"modified":"2026-03-24T22:33:42","modified_gmt":"2026-03-24T20:33:42","slug":"trivy-supply-chain-attack-spreads-via-compromised-docker-images","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/tech-news\/152987\/trivy-supply-chain-attack-spreads-via-compromised-docker-images\/","title":{"rendered":"Trivy Supply Chain Attack Spreads via Compromised Docker Images"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Threat actors compromised the Trivy vulnerability scanner version 0.69.4 on March 19, 2026, injecting credential-stealing malware into official releases.<br>&#8211; Researchers later identified additional compromised Docker images (tags 0.69.5 and 0.69.6) uploaded on March 22, which contained indicators of the TeamPCP infostealer.<br>&#8211; The attackers gained broader access, briefly exposing an internal Aqua Security GitHub organization where dozens of repositories were renamed and made public.<br>&#8211; The linked threat group, TeamPCP, has expanded its operations to include activities like ransomware deployment and attacks on Kubernetes environments.<br>&#8211; Aqua Security confirmed version 0.69.3 as the last clean release and stated its commercial products, including the Aqua Platform version of Trivy, were not impacted.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">T<\/mark>he <strong>Trivy <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/business\/151078\/trivy-scanner-compromised-in-major-supply-chain-attack\/\" class=\"acp-article-link\" data-article-id=\"151078\" title=\"Trivy Scanner Compromised in Major Supply-Chain Attack\" target=\"_blank\" rel=\"noopener noreferrer\">supply chain attack<\/a><\/strong> has escalated, with newly discovered malicious <a href=\"https:\/\/digitrendz.blog\/z\/entity\/docker\/\" class=\"acp-entity-link\" data-entity-id=\"7802\" data-entity-category=\"Technology\" title=\"Learn more about Docker\" target=\"_blank\" rel=\"noopener noreferrer\">Docker<\/a> images now circulating. Security researchers have identified additional <a href=\"https:\/\/digitrendz.blog\/z\/topic\/compromised-versions\/\" class=\"acp-topic-link\" data-topic-id=\"188596\" title=\"Explore: compromised versions\" target=\"_blank\" rel=\"noopener noreferrer\">compromised versions<\/a> of the popular vulnerability scanner, broadening the threat to development and <strong>continuous integration pipelines<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\">On March 19, attackers successfully infiltrated the official release of <a href=\"https:\/\/digitrendz.blog\/z\/entity\/trivy\/\" class=\"acp-entity-link\" data-entity-id=\"144130\" data-entity-category=\"product\" title=\"Learn more about Trivy\" target=\"_blank\" rel=\"noopener noreferrer\">Trivy<\/a> version 0.69.4, embedding malware designed to steal credentials. Following this initial breach, further investigation by the security firm <a href=\"https:\/\/digitrendz.blog\/z\/entity\/socket\/\" class=\"acp-entity-link\" data-entity-id=\"58192\" data-entity-category=\"Organization\" title=\"Learn more about Socket\" target=\"_blank\" rel=\"noopener noreferrer\">Socket<\/a> revealed that the threat actors distributed more malicious artifacts via <a href=\"https:\/\/digitrendz.blog\/z\/entity\/docker-hub\/\" class=\"acp-entity-link\" data-entity-id=\"114688\" data-entity-category=\"product\" title=\"Learn more about Docker Hub\" target=\"_blank\" rel=\"noopener noreferrer\">Docker Hub<\/a>. These new images, tagged as versions 0.69.5 and 0.69.6, were uploaded on March 22. Notably, these tags did not correspond to any official <a href=\"https:\/\/digitrendz.blog\/z\/entity\/github\/\" class=\"acp-entity-link\" data-entity-id=\"198\" data-entity-category=\"Organization\" title=\"Learn more about GitHub\" target=\"_blank\" rel=\"noopener noreferrer\">GitHub<\/a> releases, a significant red flag.<\/p>\n\n<p class=\"wp-block-paragraph\">Analysis confirmed these images contain the same <strong><a href=\"https:\/\/digitrendz.blog\/z\/topic\/indicators-of-compromise\/\" class=\"acp-topic-link\" data-topic-id=\"78444\" title=\"Explore: indicators of compromise\" target=\"_blank\" rel=\"noopener noreferrer\">indicators of compromise<\/a><\/strong> linked to the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/teampcp\/\" class=\"acp-entity-link\" data-entity-id=\"229794\" data-entity-category=\"Organization\" title=\"Learn more about TeamPCP\" target=\"_blank\" rel=\"noopener noreferrer\">TeamPCP<\/a> infostealer malware, which was central to the original campaign. The latest available tag, 0.69.6, is confirmed as malicious. In a statement on March 23, <a href=\"https:\/\/digitrendz.blog\/z\/entity\/aqua-security\/\" class=\"acp-entity-link\" data-entity-id=\"111752\" data-entity-category=\"Organization\" title=\"Learn more about Aqua Security\" target=\"_blank\" rel=\"noopener noreferrer\">Aqua Security<\/a>, Trivy&#8217;s developer, acknowledged identifying further suspicious activity involving unauthorized repository changes on March 22, behavior consistent with the known attacker&#8217;s methods.<\/p>\n\n<p class=\"wp-block-paragraph\">The scope of compromised software is now clear. Version 0.69.3 remains the last known safe release. The initially compromised version 0.69.4 has been removed from distribution, but the newly identified 0.69.5 and 0.69.6 are also affected. These malicious binaries contained <strong>typosquatted command-and-control domains<\/strong> and files for data exfiltration, pointing to repositories controlled by the attackers. Security teams emphasize that Docker tags are not immutable and should never be solely trusted for verifying integrity.<\/p>\n\n<p class=\"wp-block-paragraph\">The attack&#8217;s impact appears to extend beyond Docker. Researchers reported that an internal GitHub organization connected to Aqua Security was briefly exposed during the incident. Dozens of repositories were rapidly renamed and made public in a scripted, two-minute burst, suggesting automated activity powered by a compromised service account token. This token is believed to have been exposed during the earlier <a href=\"https:\/\/digitrendz.blog\/z\/entity\/github-actions\/\" class=\"acp-entity-link\" data-entity-id=\"76508\" data-entity-category=\"Technology\" title=\"Learn more about GitHub Actions\" target=\"_blank\" rel=\"noopener noreferrer\">GitHub Actions<\/a> breach that enabled the initial intrusion.<\/p>\n\n<p class=\"wp-block-paragraph\">This campaign is linked to the broader operations of the <a href=\"https:\/\/digitrendz.blog\/z\/topic\/teampcp-threat-group\/\" class=\"acp-topic-link\" data-topic-id=\"188593\" title=\"Explore: teampcp threat group\" target=\"_blank\" rel=\"noopener noreferrer\">TeamPCP threat group<\/a>, which has expanded from simple credential theft to more aggressive tactics. Their current activities reportedly include <strong>worm propagation, ransomware deployment, cryptocurrency mining<\/strong>, and destructive attacks aimed at Kubernetes environments. Socket advises any organization using Trivy in its CI\/CD pipelines to conduct an immediate review of recent activity and assume recent vulnerability scans may be tainted.<\/p>\n\n<p class=\"wp-block-paragraph\">Aqua Security has clarified that its commercial products, including the Trivy scanner as delivered within its proprietary Aqua Platform, show no signs of compromise from this incident. The threat is isolated to the open-source versions distributed through public channels.<\/p>\n\n<em>(Source: <a href='https:\/\/infosecurity-magazine.com\/news\/trivy-supply-chain-attack-expands\/' target='_blank'>Infosecurity Magazine<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>The Trivy supply chain attack has escalated with newly discovered malicious Docker images (versions 0.69.5 and 0.69.6) now circulating, broadening the threat to development and CI\/CD pipelines. The attack, linked to the TeamPCP threat group, involves malware designed to steal credentials and has &#8230;<\/p>\n","protected":false},"author":1,"featured_media":152986,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,3253,3297,3327,3254],"tags":[184349,182691,184350,184347,184348],"entities":[76757,44578,5009,79869,1356,49966,39639,184066,108643],"class_list":["post-152987","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-business","category-cybersecurity","category-newswire","category-technology","tag-aqua-security-incident","tag-ci-cd-pipeline-security","tag-docker-images-compromised","tag-teampcp-malware","tag-trivy-supply-chain","entity-aqua-security","entity-bluevoyant","entity-docker","entity-docker-hub","entity-github","entity-github-actions","entity-socket","entity-teampcp","entity-trivy"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/152987","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=152987"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/152987\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/152986"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=152987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=152987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=152987"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=152987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}