← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Investigating Two Variants of the Trivy Supply-Chain Compromise
In March 2026, the TeamPCP threat actor compromised the open-source vulnerability scanner Trivy, deploying credential-harvesting malware through both a compromised GitHub Action and a modified container image. This supply-chain attack directly distributed malicious payloads across various platforms, including Docker Hub and npm packages, over a period of nearly a month. The campaign utilized different attack vectors: one variant involved malicious code inserted into the `http://entrypoint.sh` of the GitHub Action, while the other involved modifications to the Trivy container's ELF binary.
Indicators of Compromise (2 / 14 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2025-53521 | — | 2026-04-02 | |
| CVE | CVE-2026-1731 | — | 2026-04-02 |