Cybersecurity & Privacy — 2026-03-22
Trivy CI/CD Supply Chain Compromised a Second Time; Malicious Payload Steals Secrets
Aqua Security's Trivy, a widely used open-source vulnerability scanner, was compromised for the second time in a month. An attacker force-pushed 75 of 76 version tags in the trivy-action GitHub repository, modifying trusted version references to serve an infostealer payload targeting CI/CD secrets. The repeated compromise of a security tool's own supply chain highlights the fragility of the open-source trust model for CI/CD pipelines.
1 sources
- Trivy supply chain compromise delivers infostealer via GitHub Actions - BleepingComputer
View in full brief →