Trivy GitHub Action Hacked: 75 Tags Hijacked. CI/CD Secrets Stolen via Security Scanner Breach.
Mar 21, 2026 // 11:34 - Lina Schonbein


Trivy, a well-known open-source tool for finding vulnerabilities supported by Aqua Security, experienced a security breach for the second time in a month, resulting in the distribution of malware designed to steal confidential CI/CD data.

The recent incident affected GitHub Actions “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,” which are used to check Docker images for weaknesses and set up GitHub Actions workflow with a specific version of the scanner, respectively.

“We discovered that an attacker used force-push to modify 75 of the 76 version tags in the aquasecurity/trivy-action repository, the official GitHub Action for running Trivy vulnerability scans in CI/CD pipelines,” said Socket security researcher Philipp Burckhardt said. “These tags were changed to distribute a malicious payload, turning trusted version references into a means of delivering an infostealer.”

The malware runs within GitHub Actions runners and intends to extract sensitive developer information from CI/CD environments, like SSH keys, credentials for cloud providers, databases, Git configurations, Docker setups, Kubernetes tokens, and cryptocurrency wallets.

This situation marks the second supply chain issue related to Trivy. Around late February and early March 2026, an automated bot named hackerbot-claw took advantage of a “pull_request_target” workflow to steal a Personal Access Token (PAT), which was then used to gain control of the GitHub repository, remove several release versions, and upload two harmful versions of its Visual Studio Code (VS Code) extension to Open VSX.

The first warning of the breach was given by security researcher Paul McCarty after a new infected release (version 0.69.4) was published to the “aquasecurity/trivy” GitHub repository. The illegitimate version has since been taken down. According to Wiz, version 0.69.4 launches both the real Trivy service and the malicious code, which performs several actions –

  • Collect data by scanning the system for environmental variables and login information, encrypting the data, and sending it via an HTTP POST request to scan.aquasecurtiy[.]org.
  • Establish persistence by using a systemd service after verifying it’s running on a developer’s machine. The systemd service is set up to execute a Python script (“sysmon.py”) that retrieves the malware from an external server and runs it. 

In a statement, Itay Shakury, vice president of open source at Aqua Security, explained that the attackers misused compromised credentials to publish malicious releases of trivy, trivy-action, and setup-trivy. In the case of “aquasecurity/trivy-action,” the attacker force-pushed 75 version tags to point to the malicious code containing the Python infostealer without creating a new release or pushing to a branch, which is the standard procedure. Seven “aquasecurity/setup-trivy” tags were force-pushed in the same way.

“So, in this instance, the attacker didn’t need to exploit Git itself,” Burckhardt told The Hacker News. “They possessed valid credentials with sufficient permissions to push code and rewrite tags, which enabled the tag poisoning we observed. The specific credential used remains unclear (e.g., a maintainer PAT vs. automation token), but the root cause is now believed to be a credential compromise stemming from the earlier incident.”

The security vendor also admitted that the recent attack resulted from insufficient containment of the hackerbot-claw incident. “We updated secrets and tokens, but the process wasn’t atomic, and attackers might have known about refreshed tokens,” Shakury stated. “We’re now adopting a more restrictive approach and locking down all automated actions and tokens to thoroughly address the issue.”

The stealer functions in three steps: gathering environment variables from the runner process memory and file system, encrypting the data, and sending it to the attacker’s server (“scan.aquasecurtiy[.]org”).

If data exfiltration fails, the victim’s GitHub account is then used to store the stolen information in a public repository called “tpcp-docs” by using the captured INPUT_GITHUB_PAT, an environment variable used in GitHub Actions to pass a GitHub PAT for authentication with the GitHub API.

The attacker’s identity is currently unknown, but there are indications that the threat actor known as TeamPCP may be responsible. This is based on the credential harvester identifying itself as “TeamPCP Cloud stealer” in the source code. Also known as DeadCatx3, PCPcat, PersyPCP, ShellForce, and CipherForce, the group is recognized as a cloud-native cybercrime platform that breaches modern cloud infrastructure for data theft and extortion.

“The credential targets in this payload align with the group’s typical cloud-native theft-and-monetization profile,” Socket stated. “The strong emphasis on Solana validator key pairs and cryptocurrency wallets is less commonly known as a TeamPCP characteristic, but it matches the group’s known financial motives. The self-labeling could be a deception, but the technical overlap with previous TeamPCP tools suggests genuine attribution might be accurate.”

Users are advised to ensure that they are using the latest safe releases –

“If compromised versions were used, treat all pipeline secrets as compromised and rotate them immediately,” Shakury warned. Other actions to take are blocking the exfiltration domain and the related IP address (45.148.10[.]212) at the network level, and checking GitHub accounts for repositories named “tpcp-docs,” which may indicate successful exfiltration via the fallback mechanism.

“Pin GitHub Actions to full SHA hashes, not version tags,” Wiz researcher Rami McCarthy advised. “Version tags can be altered to point at questionable code, as demonstrated in this attack.”

The breach on Trivy seems to have had a domino effect, with attackers using the stolen data to compromise several npm packages and push malicious versions with a self-spreading worm. More details about the issue can be found here.

#action  #breach  #ci/cd  #github  #hacked  #hijacked  #news  #scanner  #secrets  #security  #stolen  #tags.  #trivy  #via   —   News