
Trivy, a widely used open-source vulnerability scanner from Aqua Security, experienced its second compromise in a month, resulting in the distribution of malware designed to steal sensitive CI/CD secrets.
The recent incident affected GitHub Actions “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,” which are used for scanning Docker container images for weaknesses and configuring GitHub Actions workflows with a particular scanner version.
“We discovered an attacker used force-push to modify 75 of the 76 version tags in the aquasecurity/trivy-action repository, the official GitHub Action for executing Trivy vulnerability scans in CI/CD pipelines,” said Socket security researcher Philipp Burckhardt said. “These tags were changed to distribute malicious code, turning trusted version references into a method for distributing an information stealer.”
The malicious code runs within GitHub Actions runners and aims to steal important developer secrets from CI/CD environments, including SSH keys, credentials for cloud providers, databases, Git, Docker setups, Kubernetes tokens, and cryptocurrency wallets.
This event is the second supply chain attack involving Trivy. In late February and early March 2026, an automated bot named hackerbot-claw exploited a “pull_request_target” workflow to steal a Personal Access Token (PAT), which they then used to take control of the GitHub repository, remove several release versions, and upload two malicious versions of its Visual Studio Code (VS Code) extension to Open VSX.
Security researcher Paul McCarty alerted others to the first sign of compromise after a new, compromised version (0.69.4) was released to the “aquasecurity/trivy” GitHub repository. The fake version has since been removed. According to Wiz, version 0.69.4 launches both the legitimate Trivy service and the malicious code responsible for the following actions:
In a statement, Itay Shakury, VP of open source at Aqua Security, stated that attackers misused a compromised credential to publish malicious trivy, trivy-action, and setup-trivy releases. In the case of “aquasecurity/trivy-action,” the attacker force-pushed 75 version tags to point to malicious commits containing the Python infostealer payload without creating a new release or pushing to a branch, as is typically done. Seven “aquasecurity/setup-trivy” tags were modified in the same way.
“So, in this case, the attacker didn’t need to exploit Git itself,” Burckhardt told The Hacker News. “They had valid credentials with enough privileges to push code and rewrite tags, which allowed for the tag poisoning we saw. What isn’t clear is the specific credential used in this step (e.g., a maintainer PAT vs. an automation token), but credential compromise from the previous incident is understood to be the root cause.”
The security company also admitted that the latest attack resulted from an incomplete resolution of the hackerbot-claw incident. “We changed secrets and tokens, but the process wasn’t atomic, and attackers may have had access to refreshed tokens,” Shakury said. “We are now taking a more restrictive approach and locking down all automated actions and any token to thoroughly eliminate the problem.”
The stealer works in three stages: gathering environment variables from the runner process memory and the file system, encrypting the data, and sending it to the attacker’s server (“scan.aquasecurtiy[.]org”).
If the exfiltration fails, the victim’s own GitHub account is used to store the stolen data in a public repository named “tpcp-docs” using the captured INPUT_GITHUB_PAT, an environment variable in GitHub Actions that passes a GitHub PAT for authentication with the GitHub API.
The attacker’s identity isn’t currently known, although evidence suggests that TeamPCP might be responsible. This is based on the fact that the credential harvester calls itself “TeamPCP Cloud stealer” in the code. The group, also known as DeadCatx3, PCPcat, PersyPCP, ShellForce, and CipherForce, is known as a cloud-native cybercrime platform designed to break into modern cloud infrastructure to steal data and carry out extortion.
“The credential targets in this payload are consistent with the group’s broader cloud-native theft-and-monetization profile,” Socket said. “The heavy emphasis on Solana validator key pairs and cryptocurrency wallets is less well-documented as a TeamPCP hallmark, though it aligns with the group’s known financial motivations. The self-labeling could be a false flag, but the technical overlap with prior TeamPCP tooling makes genuine attribution plausible.”
Users should make sure they’re using the latest secure versions –
“If you suspect you were running a compromised version, treat all pipeline secrets as compromised and rotate them immediately,” Shakury said. Other mitigation steps include blocking the exfiltration domain and the associated IP address (45.148.10[.]212) at the network level, and checking GitHub accounts for repositories named “tpcp-docs,” which may indicate successful exfiltration via the fallback mechanism.
“Pin GitHub Actions to full SHA hashes, not version tags,” said Wiz researcher Rami McCarthy. “Version tags can be moved to point at malicious commits, as shown in this attack.”
The supply chain attack on Trivy seems to have led to a wider impact, as attackers have used the stolen data to compromise several npm packages and upload malicious versions containing a self-spreading worm. More details about the activity can be found here.
#action #ci/cd #github #hacked #hijacked #news #secrets #stolen #tags. #trivy #via — News
© Bulletproof Servers. All rights reserved.