PULSE NAME
Guidance for detecting, investigating, and defending against the Trivy supply chain compromise
WHITE TeamPCP AlienVault 2026-03-25 Modified: 2026-03-25
7
IOCs
LOW VOLUME
On March 19, 2026, Trivy, an open-source vulnerability scanner, was compromised in a sophisticated CI/CD supply chain attack. Threat actors, identified as TeamPCP, injected credential-stealing malware into official Trivy releases, affecting the core binary and GitHub Actions. The attack exploited mutable tags and commit identity spoofing on GitHub. The malware performed extensive credential harvesting, targeting cloud providers, Kubernetes secrets, and various application credentials. Microsoft Defender provides detection and investigation capabilities for this threat. Recommended mitigations include updating to safe versions, hardening CI/CD pipelines, enforcing least privilege, protecting secrets, and leveraging attack path analysis to reduce lateral movement risks.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Trivy
Indicators of Compromise (7)
All IPv4 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
IPv4 45.148.10.212 2026-03-25
IPv4 45.148.10.122 2026-03-25
domain aquasecurtiy.org 2026-03-25
domain checkmarx.zone 2026-03-25
hostname plug-tab-protective-relay.trycloudflare.com 2026-03-25
hostname scan.aquasecurtiy.org 2026-03-25
hostname tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io 2026-03-25