Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets
Blog post from Socket
A recent supply chain attack has targeted Trivy, specifically its GitHub Actions, posing a significant threat to its ecosystem by injecting a malicious payload into 75 out of 76 version tags of the aquasecurity/trivy-action repository. This attack, the second of its kind in March, leverages force-pushed tags to execute an infostealer before legitimate Trivy scans, potentially affecting over 10,000 GitHub workflows. The malicious payload is designed to extract sensitive data such as SSH keys, cloud credentials, and Kubernetes tokens from CI/CD environments, employing techniques like memory dumping and filesystem credential harvesting. The compromised tags, except for version 0.35.0, have been modified to distribute malware, which encrypts and exfiltrates data to a typosquat domain, with a fallback option using the victim's GitHub account. The attack was facilitated by residual access to credentials compromised earlier in March, and users are advised to pin actions to specific commit SHAs or use the unaffected version tag to mitigate the risk.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 11 | 1,488 | 268 | 99 | +7% |
| Kubernetes | 4 | 1,840 | 308 | 106 | +33% |
| AI Coding Assistant | 1 | 1,255 | 319 | 126 | +24% |
| Real-time | 1 | 6,457 | 1,307 | 242 | +28% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.