Skip to content

Aqua Security

Disclosed Mar 21, 20266 months agoUnverified

Trivy scanner releases and GitHub Actions hijacked to push credential stealer

TeamPCP used credentials taken in a March 1 intrusion to publish a malicious Trivy v0.69.4 release and force-push 75 of 76 trivy-action tags, spreading an infostealer that harvested cloud, SSH, Kubernetes and CI/CD secrets. Aqua Security said its earlier containment was incomplete; stolen secrets were later used against Cisco and the European Commission.

What is known

People affectedNot stated in the sources we have
DisclosedMar 21, 2026
DiscoveredMar 1, 2026
AttackSupply chain
Data exposedCredentials and tokens, API keys
SectorTech · IL
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Part ofTrivy (2026)

Sources

Notices filed

WhereFiledPeople
ResearchtotalMar 21

Same campaign

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Aqua Security

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.