#trivy


Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Aug 12, 2026 // 11:15

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, […]

TeamPCP backdoors LiteLLM 1.82.7-1.82.8. Possible Trivy CI/CD compromise suspected.

Mar 24, 2026 // 22:33

The hacker group TeamPCP, responsible for past issues with Trivy and KICS, has now infiltrated the popular Python package litellm. They introduced two harmful versions […]

TeamPCP backdoors LiteLLM 1.82.7-1.82.8, likely via Trivy CI/CD breach.

Mar 24, 2026 // 22:24

The hacking group TeamPCP, known for recently breaching Trivy and KICS, has now infiltrated a widely used Python package called litellm. They introduced two infected […]

Trivy Supply Chain Attack: Docker, GitHub Impacted. OR Trivy Hacked: Docker & GitHub Supply Chain Affected.

Mar 24, 2026 // 10:58

The TeamPCP hackers, responsible for the Trivy supply-chain attack, kept targeting Aqua Security by uploading harmful Docker images and taking control of the GitHub organization […]

Trivy Hack: Docker Infostealer, Worm, & Kubernetes Wiper Deployed

Mar 23, 2026 // 11:33

Following the Trivy supply chain attack, security experts have detected harmful components spread via Docker Hub, indicating a widespread impact on development environments. The last […]

Trivy security flaw exploited: GitHub Actions pushed info-stealing malware.

Mar 22, 2026 // 14:37

The security tool Trivy was targeted in a supply-chain attack by a group called TeamPCP. They spread malware that steals credentials through official releases and […]

Trivy GitHub Action Hacked: 75 Tags Hijacked. CI/CD Secrets Stolen via Security Scanner Breach.

Mar 21, 2026 // 11:34

Trivy, a well-known open-source tool for finding vulnerabilities supported by Aqua Security, experienced a security breach for the second time in a month, resulting in […]

Trivy Flaw Sparks Widespread npm CanisterWorm Outbreak Supply Chain Attack via Trivy Impacts 47 Packages

Mar 21, 2026 // 11:33

The individuals responsible for the supply chain attack that targeted the widely used Trivy scanner are believed to be launching additional attacks. These attacks have […]

Trivy GitHub Action Hacked; CI/CD Secrets Stolen via 75 Hijacked Tags.

Mar 21, 2026 // 11:24

Trivy, a widely used open-source vulnerability scanner from Aqua Security, experienced its second compromise in a month, resulting in the distribution of malware designed to […]

Trivy Flaw Sparks npm Worm: CanisterWorm Infects 47 Packages, Spreads Rapidly.

Mar 21, 2026 // 11:24

The individuals responsible for the supply chain attack on the Trivy scanner are believed to be launching additional attacks, compromising numerous npm packages with a […]