Trivy Supply Chain Attack: Docker, GitHub Impacted. OR Trivy Hacked: Docker & GitHub Supply Chain Affected.
Mar 24, 2026 // 10:58 - Lina Schonbein


The TeamPCP hackers, responsible for the Trivy supply-chain attack, kept targeting Aqua Security by uploading harmful Docker images and taking control of the GitHub organization to alter multiple repositories.

This follows the attacker’s successful compromise of the GitHub build process for Trivy, Aqua Security’s vulnerability scanner, using it to spread malware that steals information. This supply-chain attack then affected Docker Hub over the weekend.

Trivy is a popular tool, with over 33,800 stars on GitHub, commonly used to find weaknesses, configuration problems, and exposed secrets in software and infrastructure.

Socket, a company focused on supply-chain security, reported on Sunday that it found compromised Trivy files on Docker Hub.

“New image tags 0.69.5 and 0.69.6 were uploaded on March 22 without corresponding GitHub releases or tags,” Socket researchers state. Their analysis revealed that these two images showed signs of being related to the info-stealing malware TeamPCP spread after gaining access to Aqua Security’s GitHub organization.

The researchers pointed out that the most recent official Trivy release is 0.69.3 and cautioned that even though they didn’t find evidence of older images or files being altered after release, “Docker Hub tags can be changed, and organizations shouldn’t rely only on tag names to ensure integrity.”

On March 20, Aqua Security stated that the attacker gained unauthorized access to their GitHub organization due to incomplete containment of a previous incident targeting Trivy itself earlier in the month.

This allowed the attacker to insert code into Trivy to steal credentials (TeamPCP Cloud stealer) and release malicious versions of the tool.

Aqua responded to this by releasing new, secure versions of Trivy on March 20 and hiring Sygnia, an incident response company, to help with security measures and investigation.

However, in a new update, Aqua mentioned they detected more suspicious activity on March 22, suggesting that the same attackers had regained unauthorized access and made “unauthorized changes and repository tampering.”

The company clarified that despite this, Trivy itself was not affected this time.

An analysis from OpenSourceMalware, a malware intelligence platform driven by the community, explained that TeamPCP broke into the *aquasec-com* GitHub organization, where Aqua Security hosts its private code, as opposed to the company’s *aquasecurity* GitHub organization, which is for public repositories.

Using an automated script, the hackers took only two minutes to add the prefix *tpcp-docs-* to all 44 repositories in the company’s GitHub organization and change all of their descriptions to say “TeamPCP Owns Aqua Security.”

The researchers are very confident that the attacker gained access by compromising a service account called Argon-DevOps-Mgt, which could access both of Aqua Security’s GitHub organizations.

According to OpenSourceMalware, the compromised service account used a Personal Access Token (PAT) of a regular user instead of a more secure GitHub App to authorize actions.

The problem with PATs is that they function like passwords and remain valid for a much longer time than the token of a GitHub App. Furthermore, service accounts are often used for automated tasks and lack multi-factor authentication (MFA) protection.

To verify that the account had admin permissions for both public and private AquaSec GitHub organizations, TeamPCP created a new branch called *update-plugin-links-v0.218.2* in the public *aquasecurity/trivy-plugin-aqua* repository, which they then deleted “at the exact same second.”

The researchers believe the hackers obtained the PAT for the Argon-DevOps-Mgt service account via the TeamPCP Cloud stealer, which gathers GitHub tokens, SSH keys, cloud credentials, and environment variables from CI runners.

“As a service account that triggers workflows on *trivy-plugin-aqua*, its token was present in the runner environment,” OpenSourceMalware explains.

OpenSourceMalware has provided a list of indicators of compromise to help security teams determine if their systems have been affected by this supply-chain attack.

Aqua Security claims there is no evidence to suggest that the Trivy version used in its commercial products was compromised. “By design, the version used in Aqua’s commercial platform is behind the open-source version of Trivy because of a controlled integration process.”

However, the company promised to provide updates as more details become available and to release additional findings on Tuesday, at the end of the day.

#affected.  #attack  #chain  #docker  #github  #hacked  #impacted. or trivy  #news  #supply  #trivy   —   News