Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack
wiz.io | incident | #cloud | #supply-chain | #github-actions | #incident | #trivy | #teampcp | #aqua-security | #docker-hub
Summary
Recapping the March 2026 Trivy compromise: TeamPCP injected malware into the scanner, trivy-action, and setup-trivy, and later fake Docker Hub images, harvesting cloud and CI/CD credentials.
- Published
- Collected
Skip to content