Aqua Security Trivy Compromised, Secrets Stolen
Aqua Security’s Trivy scanner has been compromised in a recent supply chain attack, highlighting vulnerabilities in open-source infrastructure. A cybercriminal infiltrated Trivy by exploiting a misconfiguration in the GitHub Actions environment. This breach began in late February 2026, leading to the hijack of credentials and distribution of malicious software versions. The compromised version, v0.69.4, disguised malware that collected sensitive information, such as API tokens and cloud credentials, from CI/CD pipelines.
The attackers manipulated existing version tags to inject this malicious code silently, ensuring organizations continued using compromised workflows. Aqua Security’s commercial products remained unaffected due to isolated architectures. Collaboration with Sygnia and security partners accelerated response efforts to mitigate damage. Security teams are advised to replace compromised versions with secure ones and rotate any exposed credentials. The incident underscores the importance of vigilance, especially for open-source projects, in safeguarding against supply chain attacks.
For a full report, visit the complete article: https://cybersecuritynews.com/trivy-scanner-compromised/
