Trivy security flaw exploited: GitHub Actions pushed info-stealing malware.
Mar 22, 2026 // 14:37 - Lina Schonbein


The security tool Trivy was targeted in a supply-chain attack by a group called TeamPCP. They spread malware that steals credentials through official releases and GitHub Actions.

Trivy is a widely-used scanner that finds vulnerabilities, misconfigurations, and exposed secrets in containers, Kubernetes, code repositories, and cloud setups. Its popularity makes it a prime target for attackers seeking sensitive authentication information.

Security expert Paul McCarty first reported the breach, warning that Trivy version 0.69.4 was compromised, with malicious container images and GitHub releases being distributed.

Analyses by Socket and Wiz revealed that the attack impacted multiple GitHub Actions, affecting almost all version tags in the trivy-action repository.

Researchers discovered that the attackers had infiltrated Trivy’s GitHub build process. They replaced the entrypoint.sh file in GitHub Actions with a malicious version and released infected binaries in Trivy v0.69.4. These acted as information stealers across the main scanner and related GitHub Actions like trivy-action and setup-trivy.

The attackers exploited a compromised credential with write access to the repository to publish the malicious releases. These credentials came from a previous breach in March, where credentials from Trivy’s environment were stolen and not fully secured.

The attackers forcibly pushed 75 out of 76 tags in the aquasecurity/trivy-action repository, pointing them to malicious commits.

Consequently, any external workflows using these tags unknowingly ran the malicious code before executing legitimate Trivy scans, making the compromise tough to spot.

Socket says the infostealer gathered reconnaissance data and scanned systems for files and locations that typically store credentials and secrets, like:

  • Reconnaissance data: hostname, user info, system info, network settings, and environment variables
  • SSH: private and public keys and config files
  • Cloud and infrastructure configs: Credentials for Git, AWS, GCP, Azure, Kubernetes, and Docker
  • Environment files: .env and similar files
  • Database credentials: config files for PostgreSQL, MySQL/MariaDB, MongoDB, and Redis
  • Credential files: including authentication tokens for package managers and Vault
  • CI/CD configurations: Terraform, Jenkins, GitLab CI, and related files
  • TLS private keys
  • VPN configurations
  • Webhooks: Tokens for Slack and Discord
  • Shell history files
  • System files: /etc/passwd, /etc/shadow, and authentication logs
  • Cryptocurrency wallets

The malicious script also examined memory used by the GitHub Actions Runner.Worker process to find JSON strings like “" <name> ":{ "value": "<secret>", "isSecret":true}” to uncover more secrets.

On developer machines, the compromised Trivy binary did similar things, collecting environment variables, scanning files for credentials, and listing network interfaces.

The collected data was encrypted and saved in a file called tpcp.tar.gz, which was then sent to a fake command-and-control server at scan.aquasecurtiy[.]org.

If sending the data failed, the malware made a public repository named tpcp-docs on the victim’s GitHub account and put the stolen data there.

To stay on a compromised device, the malware also put a Python script at ~/.config/systemd/user/sysmon.py and registered it as a systemd service. This script would check a remote server for more payloads to install, giving the attacker ongoing access to the device.

The attack is thought to be linked to TeamPCP because one of the infostealer payloads used in the attack has a comment saying “TeamPCP Cloud stealer” at the end of the Python script.

“The malware identifies itself as TeamPCP Cloud stealer in a Python comment. TeamPCP, also known as DeadCatx3, PCPcat, and ShellForce, is a known cloud threat actor that exploits misconfigured Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers,” Socket explains.

Aqua Security acknowledged the incident, stating that an attacker used compromised credentials from the previous, incompletely contained incident.

“This was a follow up from the recent incident (2026-03-01) which exfiltrated credentials. Our containment of the first incident was incomplete,” explained Aqua Security.

“We rotated secrets and tokens, but the process wasn’t atomic and attackers may have been privy to refreshed tokens.”

The malicious Trivy release (v0.69.4) was available for about three hours, and the compromised GitHub Actions tags were active for up to 12 hours.

The attackers also messed with the project’s repository, deleting Aqua Security’s original announcement of the earlier incident in March.

Organizations that used affected versions during the incident should assume their environments are entirely compromised.

This means changing all secrets like cloud credentials, SSH keys, API tokens, and database passwords, and checking systems for further compromise.

Researchers at Aikido have also connected the same attacker to a follow-up attack with a new self-spreading worm called “CanisterWorm,” which targets npm packages.

The worm compromises packages, installs a persistent backdoor through a systemd user service, and uses stolen npm tokens to release malicious updates to other packages.

“Self-spreading worm. deploy.js takes npm tokens, gets usernames, lists all publishable packages, increases patch versions, and releases the payload across the entire scope. 28 packages in under 60 seconds,” Aikido points out.

The malware uses a decentralized command-and-control system with Internet Computer (ICP) canisters, which serve as a dead-drop resolver, providing URLs for further payloads. 

Using ICP canisters makes the operation harder to shut down because only the canister’s controller can remove it, and any attempt to stop it would require a governance proposal and network vote.

The worm can also steal npm authentication tokens from config files and environment variables, allowing it to spread across developer environments and CI/CD pipelines.

At the time of analysis, some of the secondary payload infrastructure was inactive or using harmless content, but researchers say this could change at any time.

#actions  #exploited  #flaw  #github  #info-stealing  #malware  #news  #pushed  #security  #trivy   —   News