
Following the Trivy supply chain attack, security experts have detected harmful components spread via Docker Hub, indicating a widespread impact on development environments.
The last safe Trivy version on Docker Hub is 0.69.3. The compromised versions 0.69.4, 0.69.5, and 0.69.6 have been removed from the container image repository.
“New image tags 0.69.5 and 0.69.6 appeared on March 22 without matching updates or tags on GitHub. Both images showed signs of compromise linked to the TeamPCP information-stealing malware seen previously in this campaign,” reported Socket security researcher Philipp Burckhardt .
This follows a supply chain issue affecting Trivy, a well-known open-source tool for finding vulnerabilities, managed by Aqua Security. Attackers exploited a compromised login to inject a credential-stealing program into infected versions of the tool and two related GitHub Actions, namely “aquasecurity/trivy-action” and “aquasecurity/setup-trivy.”
The attack’s effects have spread, with hackers using the stolen information to compromise many npm packages and distribute a self-replicating worm named CanisterWorm. The incident is attributed to a threat actor identified as TeamPCP.
The OpenSourceMalware team reported that attackers vandalized all 44 internal repositories of Aqua Security’s “aquasec-com” GitHub organization by renaming them with “tpcp-docs-” prefixes, changing all descriptions to “TeamPCP Owns Aqua Security,” and making them public.
All repositories were reportedly changed within a quick, scripted two-minute span between 20:31:07 UTC and 20:32:26 UTC on March 22, 2026. It is believed that the attackers used a compromised “Argon-DevOps-Mgt” service account to do this.
“Our analysis of the GitHub Events API suggests that a compromised service account token — probably obtained during TeamPCP’s earlier compromise of Trivy GitHub Actions — allowed the attack,” explained security researcher Paul McCarty . “This is a service/bot account (GitHub ID 139343333, created 2023-07-12) that is important because it connects both GitHub organizations.”
“A single hacked token for this account granted the attacker write/admin access to both organizations,” McCarty added.
This incident is the latest development from a threat actor known for targeting cloud infrastructures and increasingly developing methods to systematically exploit Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers to steal data, deploy ransomware, extort victims, and mine cryptocurrency.
Their increasing sophistication is highlighted by a new destructive malware that spreads through SSH using stolen keys and exploits exposed Docker APIs on port 2375 within the local network.
A new program linked to TeamPCP has been found to expand beyond data theft to wipe entire Kubernetes (K8s) clusters based in Iran. The shell script uses the same ICP canister connected to CanisterWorm and checks for Iranian systems.
“On Kubernetes: it deploys privileged DaemonSets across every node, including the control plane,” stated Aikido security researcher Charlie Eriksen . “Iranian nodes undergo a wipe and are force-rebooted using a container named ‘kamikaze.’ Non-Iranian nodes get CanisterWorm installed as a systemd service. Non-K8s Iranian hosts are subjected to ‘rm -rf / –no-preserve-root.'”
Given the ongoing nature of the attack, it is critical for organizations to review their use of Trivy in CI/CD pipelines, avoid using the affected versions, and consider recent executions potentially compromised.
“This compromise showcases the lasting impact of supply chain attacks,” OpenSourceMalware stated. “A login obtained during the Trivy GitHub Actions compromise months ago was used to deface an entire internal GitHub organization. The Argon-DevOps-Mgt service account — a single bot account connecting two organizations with a long-lived PAT — was the vulnerability.”
“From cloud exploitation to supply chain worms to Kubernetes wipers, they are building capabilities and targeting the security vendor ecosystem itself. The irony of a cloud security company being compromised by a cloud-native threat actor should not be overlooked by the industry.”
#deployed #docker #hack. #infostealer #kubernetes #news #trivy #wiper #worm — News
© Bulletproof Servers. All rights reserved.