Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets

Blog post from Socket

Post Details
Company
Date Published
Author
Philipp Burckhardt
Word Count
3,346
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent supply chain attack has targeted Trivy, specifically its GitHub Actions, posing a significant threat to its ecosystem by injecting a malicious payload into 75 out of 76 version tags of the aquasecurity/trivy-action repository. This attack, the second of its kind in March, leverages force-pushed tags to execute an infostealer before legitimate Trivy scans, potentially affecting over 10,000 GitHub workflows. The malicious payload is designed to extract sensitive data such as SSH keys, cloud credentials, and Kubernetes tokens from CI/CD environments, employing techniques like memory dumping and filesystem credential harvesting. The compromised tags, except for version 0.35.0, have been modified to distribute malware, which encrypts and exfiltrates data to a typosquat domain, with a fallback option using the victim's GitHub account. The attack was facilitated by residual access to credentials compromised earlier in March, and users are advised to pin actions to specific commit SHAs or use the unaffected version tag to mitigate the risk.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 11 1,488 268 99 +7%
Kubernetes 4 1,840 308 106 +33%
AI Coding Assistant 1 1,255 319 126 +24%
Real-time 1 6,457 1,307 242 +28%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.