Aqua Security
Disclosed Mar 21, 20266 months agoUnverified
Trivy scanner releases and GitHub Actions hijacked to push credential stealer
TeamPCP used credentials taken in a March 1 intrusion to publish a malicious Trivy v0.69.4 release and force-push 75 of 76 trivy-action tags, spreading an infostealer that harvested cloud, SSH, Kubernetes and CI/CD secrets. Aqua Security said its earlier containment was incomplete; stolen secrets were later used against Cisco and the European Commission.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 21, 2026 |
| Discovered | Mar 1, 2026 |
| Attack | Supply chain |
| Data exposed | Credentials and tokens, API keys |
| Sector | Tech · IL |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Part of | Trivy (2026) |
Sources
| Source | |
|---|---|
| Trivy vulnerability scanner breach pushed infostealer via GitHub Actionsbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Mar 21 |
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| Apr 265 months ago | Supply chain | Tech | Confirmed | Unknown | |
| Mar 315 months ago | Supply chain | Tech | Unverified | Unknown | |
| Mar 276 months ago | Supply chain | Government | Confirmed | Unknown | |
| Mar 246 months ago | Supply chain | AI | Unverified | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.