<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Trivy Supply Chain Attack Expands With New Compromised Docker Images

"Trivy supply chain attack: Malicious Docker images found. Aqua Security's vulnerability scanner compromised. Check CI/CD pipelines now."
Content Team

The Trivy supply chain attack has escalated with new compromised Docker images discovered on March 22, 2026. After initially compromising Aqua Security's vulnerability scanner version 0.69.4 on March 19, attackers uploaded malicious versions 0.69.5 and 0.69.6 to Docker Hub without corresponding GitHub releases.

Socket researchers confirmed both images contain TeamPCP infostealer malware with credential-stealing capabilities. The attack expanded beyond Docker images when attackers briefly exposed Aqua Security's internal GitHub organization, renaming dozens of repositories in a two-minute automated burst.

Version 0.69.3 remains the last clean release, while 0.69.4 through 0.69.6 are confirmed compromised. Organizations using Trivy in CI/CD pipelines should review recent activity and treat recent scans as potentially compromised. Aqua's commercial products remain unaffected.

Source: Infosecurity Magazine

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo