Trivy Supply Chain Attack Expands to Compromised Docker Images
Blog post from Socket
Socket's threat research team has uncovered further compromised Trivy artifacts on Docker Hub following a GitHub Actions breach affecting the aquasecurity/trivy-action repository. New compromised image tags, 0.69.5 and 0.69.6, were identified with indicators of compromise linked to the TeamPCP infostealer, similar to prior stages of the campaign, and are associated with a typosquatted C2 domain and exfiltration artifacts. The Aqua Security GitHub organization was reportedly temporarily exposed, increasing concerns about the level of access obtained by the attacker. While versions 0.69.3 and earlier remain unmodified, tags 0.69.4 to 0.69.6 are compromised, and organizations should not solely rely on tag names for integrity due to the non-immutable nature of Docker Hub tags. Many images, including official builds and third-party derivatives, might have incorporated malicious binaries if they were automatically updated during the attack window. Precautionary measures are being taken, including revoking tokens and adopting trusted publishing practices, while organizations are advised to review their Trivy usage in CI/CD pipelines and track affected artifacts through ongoing campaign updates.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.