Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Trivy Supply Chain Attack Expands to Compromised Docker Images

Blog post from Socket

Post Details
Company
Date Published
Author
Philipp Burckhardt
Word Count
366
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's threat research team has uncovered further compromised Trivy artifacts on Docker Hub following a GitHub Actions breach affecting the aquasecurity/trivy-action repository. New compromised image tags, 0.69.5 and 0.69.6, were identified with indicators of compromise linked to the TeamPCP infostealer, similar to prior stages of the campaign, and are associated with a typosquatted C2 domain and exfiltration artifacts. The Aqua Security GitHub organization was reportedly temporarily exposed, increasing concerns about the level of access obtained by the attacker. While versions 0.69.3 and earlier remain unmodified, tags 0.69.4 to 0.69.6 are compromised, and organizations should not solely rely on tag names for integrity due to the non-immutable nature of Docker Hub tags. Many images, including official builds and third-party derivatives, might have incorporated malicious binaries if they were automatically updated during the attack window. Precautionary measures are being taken, including revoking tokens and adopting trusted publishing practices, while organizations are advised to review their Trivy usage in CI/CD pipelines and track affected artifacts through ongoing campaign updates.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.