← Incident database

trivy-supply-chain-2026 · Disclosed 2026-03-20

Trivy: residual credentials used to tamper with releases and actions

Aqua reports privileged-token theft through GitHub Actions misconfiguration, incomplete initial rotation, and renewed release tampering. Existing action tags were redirected to malicious commits.

Supply chain / CICredentialsConfiguration / exposure

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Aqua describes late-February token theft, credentials remaining valid after March 1 rotation, and reuse for March 19 tampering.

    [s2]Attack Timeline
  • Reported fact

    Malicious Trivy v0.69.4 and actions were distributed, including changed existing tags; Aqua warns that secrets accessible to affected runners must be considered exposed.

    [s2]What Happened / What Was Affected

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Aqua reported artifact removal, credential revocation and rotation, moving away from long-lived tokens, and strengthening CI and access controls.

    [s2]Ongoing Actions / Attack Timeline

Evidence relevant to prevention

Operational controls to inspect

Inspect verified commit pinning rather than tag names alone, and reconcile every old credential’s revocation with its consumers.

Editorial assessment; not a determination of liability. [s2]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

The exact late-February entry day is unknown. This record focuses on the March 19 recurrence; distribution counts are not victim-organization counts.

Sources

  1. [s1] Aqua Security / Trivy maintainers · Primary source

    Trivy Security incident 2026-03-19 ↗

    Published 2026-03-20 · Reviewed 2026-10-02

  2. [s2] Aqua Security · Primary source

    Trivy supply chain attack: ongoing investigation and remediation ↗

    Published 2026-03-22 · Reviewed 2026-10-02