← Aqua Security

2026 Aqua Security — Trivy supply-chain compromise (v0.69.4, GitHub Actions)

2026 Unknown records affected Share on X

Data compromised

CI/CD and developer secrets (varies by victim pipeline); not a classic single consumer PII count

Technical writeup

In March 2026, Aqua Security disclosed a supply-chain attack on the Trivy vulnerability scanner ecosystem. Malicious artifacts were published for Trivy v0.69.4 and multiple trivy-action and setup-trivy GitHub Action tags; attackers used stolen credentials to replace release tags with infostealer code that ran in CI/CD before legitimate scans. Exposed secrets could include GitHub tokens, cloud credentials, SSH keys, and Kubernetes tokens. Aqua Security removed malicious artifacts, published security advisories, and recommended rotating pipeline secrets and pinning Actions to verified commit SHAs. Widely reported by BleepingComputer, Ars Technica, and Snyk (March 19–21, 2026).

Root cause

Supply-chain attack; compromised release tags and GitHub Actions; credential theft malware

References