PULSE NAME
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack
WHITE Teampcp PetrP.73 2026-03-24 Modified: 2026-04-23
97
IOCs
HIGH VOLUME
On March 19, 2026, a sophisticated supply chain attack was conducted against Aqua Security's Trivy vulnerability scanner, resulting in the injection of credential-stealing malware across several components of the Trivy project, including the core scanner and its GitHub Actions. The threat actor, identified as TeamPCP, executed the attack by making fraudulent commits and pushing malicious versions of the Trivy repository, specifically tagging v0.69.4. This led to the distribution of compromised binaries and scripts through GitHub Releases, Docker Hub, and other channels.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (1 / 97 total)
All hostname FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 805c08686e755c063a0bb460bdf9dcc4 MD5 of 822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0 2026-03-24