trivy-supply-chain-2026 · Disclosed 2026-03-20
Trivy: residual credentials used to tamper with releases and actions
Aqua reports privileged-token theft through GitHub Actions misconfiguration, incomplete initial rotation, and renewed release tampering. Existing action tags were redirected to malicious commits.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Aqua describes late-February token theft, credentials remaining valid after March 1 rotation, and reuse for March 19 tampering.
[s2]Attack Timeline - Reported fact
Malicious Trivy v0.69.4 and actions were distributed, including changed existing tags; Aqua warns that secrets accessible to affected runners must be considered exposed.
[s2]What Happened / What Was Affected
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Aqua reported artifact removal, credential revocation and rotation, moving away from long-lived tokens, and strengthening CI and access controls.
[s2]Ongoing Actions / Attack Timeline
Evidence relevant to prevention
Operational controls to inspect
Inspect verified commit pinning rather than tag names alone, and reconcile every old credential’s revocation with its consumers.
Editorial assessment; not a determination of liability. [s2]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
The exact late-February entry day is unknown. This record focuses on the March 19 recurrence; distribution counts are not victim-organization counts.
Sources
[s1] Aqua Security / Trivy maintainers · Primary source
Trivy Security incident 2026-03-19 ↗Published 2026-03-20 · Reviewed 2026-10-02
[s2] Aqua Security · Primary source
Trivy supply chain attack: ongoing investigation and remediation ↗Published 2026-03-22 · Reviewed 2026-10-02