Trivy 遭入侵:最新供应链攻击全解析
wiz.io | 事件 | #cloud | #supply-chain | #github-actions | #incident | #trivy | #teampcp | #aqua-security | #docker-hub
摘要
2026 年 3 月 Trivy 供应链攻击全景:TeamPCP 把凭证窃取木马注入扫描器本体、trivy-action 与 setup-trivy,随后又在 Docker Hub 投递恶意镜像,窃取云密钥、SSH 密钥与 CI/CD 机密,并持续展示对上游的访问能力。
- 发布时间
- 收录时间
Skip to content