The Trivy Supply Chain Attack
Updated 5 Oct 2026 · Incident date 19 Mar 2026 · CI action
trivy 0.69.3 -> 0.69.4 (also trivy-action tags before 0.35.0 and setup-trivy before 0.2.6)trivy binary and trivy-action tagsThe Trivy supply chain attack on 19 March 2026 turned a security scanner into a credential stealer. An attacker used stolen credentials to publish a malicious Trivy v0.69.4 release. The same attacker moved 76 of 77 version tags in aquasecurity/trivy-action and all 7 tags in aquasecurity/setup-trivy to malicious commits. The GitHub advisory is GHSA-69fq-xp46-6x23 and carries the CVE id CVE-2026-33634.
A group that calls itself TeamPCP did this. It read secrets from CI jobs that ran Trivy. Five days later it used one of those secrets to publish a poisoned LiteLLM release, see the LiteLLM PyPI attack. This page gives the timeline, the indicators, the safe versions and the steps to check your pipelines.
What happened to Trivy
Attackers used stolen credentials to push credential-stealing code into three Trivy distribution channels at once. Trivy is an open-source vulnerability scanner from Aqua Security, so it often runs in CI with access to secrets. That access is what the attackers wanted. The advisory lists the affected parts:
| Component | Compromised | Safe |
|---|---|---|
| Trivy binary and container image | v0.69.4, v0.69.5, v0.69.6 | v0.69.2, v0.69.3 |
aquasecurity/trivy-action | All tags before 0.35.0 | v0.35.0 |
aquasecurity/setup-trivy | All versions not pinned by SHA | v0.2.6 |
The v0.69.4 release reached GitHub, Docker Hub and package managers. Microsoft reports that the malicious code ran in addition to the real Trivy scan, so a workflow looked successful while it leaked secrets.
On a GitHub-hosted runner the code dumped the memory of the Runner.Worker process and searched it for secrets in the form {"value":"...","isSecret":true}. On other systems it searched the file system for SSH keys, cloud credentials, Kubernetes tokens, Docker configuration and cryptocurrency wallets. It encrypted the data with AES-256-CBC and a 4096-bit RSA key, and sent it to a lookalike domain, scan.aquasecurtiy.org. Note the misspelling. If that failed, it created a public repository named tpcp-docs in the victim's own GitHub account and stored the data there. Snyk describes the same behavior.
On developer machines the malware also left a Python dropper at ~/.config/systemd/user/sysmon.py. Wiz reports that it contacted an Internet Computer canister for new payloads.
Timeline of the compromise
The compromise started in late February and ran in three stages until 23 March 2026. Snyk and the GitHub advisory give these dates. Times are UTC.
| Date | Event |
|---|---|
| Late February | An attacker abuses a misconfigured pull_request_target workflow in the Trivy repository. It steals an organization-wide personal access token of the aqua-bot service account. |
| 1 March | Using that access, the attacker makes the Trivy repository private for a time, deletes releases and publishes a malicious VS Code extension. Some refreshed tokens stay valid. |
| 19 March, about 17:43 | Malicious commits go to trivy-action and setup-trivy. Tags are rewritten. |
| 19 March, 18:22 | Trivy v0.69.4 becomes public on several channels. |
| 20 March, about 05:40 | The trivy-action exposure ends after clean-up. That is about 12 hours. |
| 21 March | GitHub publishes advisory GHSA-69fq-xp46-6x23. |
| 22 to 23 March | Aqua finds and removes more malicious Docker Hub images, v0.69.5 and v0.69.6. |
| 24 March | Poisoned LiteLLM releases appear on PyPI. |
The forged commits had clear marks. Snyk lists unsigned commits where real releases carried GPG signatures, impossible timestamps between a commit and its parent, and single-file changes where real commits changed many files.
Indicators of compromise
Search your logs and your GitHub organization for the items below. They come from the GitHub advisory and Wiz.
- Exfiltration domain:
scan.aquasecurtiy.org, IP45.148.10.212 - Payload channel on the Internet Computer:
tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io - Tunnel host:
plug-tab-protective-relay.trycloudflare.com - GitHub repositories named with the prefix
tpcp-docs, with release assets taggeddata-<timestamp> - Dropper file:
~/.config/systemd/user/sysmon.py - Binary: Trivy v0.69.4, v0.69.5 or v0.69.6. SHA-256 of the Linux 64-bit tarball of v0.69.4:
385d498d18a3a7c67878ca7322716f9da25683eb1a4bf9e9592da0d5f2ab09f6 - Workflow runs on 19 and 20 March 2026 that used
trivy-actionorsetup-trivyby tag
Is Trivy still compromised?
No. Aqua Security removed the malicious components from its distribution channels, and clean versions are available. The advisory lists Trivy v0.69.2 and v0.69.3, trivy-action v0.35.0 and setup-trivy v0.2.6 as safe. It warns that the bad files can persist in intermediary caches, such as a mirror or a build cache.
Aqua replaced the original trivy-action tags with v-prefixed tags because of immutability limits. Snyk reports that Aqua enabled immutable releases so that tags cannot be force-pushed again. Check that your workflow uses a safe reference. A workflow that ran a bad version on 19 or 20 March stays exposed even though Trivy itself is clean now. The secrets that job held must be rotated.
Use only the safe versions the advisory names.
How to check your CI pipelines
Find every workflow that uses Trivy, then read the run logs from 19 and 20 March 2026. Microsoft publishes guidance for detecting and investigating the Trivy compromise. Its hunting signs include process discovery of Runner.Worker, decoded base64 Python payloads and encrypted archives named tpcp.tar.gz.
Start with a search of the workflow files in each repository. These commands only read files.
grep -rn "aquasecurity/trivy-action\|aquasecurity/setup-trivy" .github/workflows/ gh repo list YOUR-ORG --limit 1000 --json name -q '.[].name' | grep tpcp-docs
The first line shows which workflows use the actions and how they reference them. Any reference by tag, other than @v0.35.0 for trivy-action, is at risk. The second line looks for the fallback repositories the malware created. Replace YOUR-ORG with your organization name. A match means the malware ran and stored stolen data in your account.
Then look for the tool itself. Run trivy --version on build servers and developer machines. Check container images and caches for v0.69.4, v0.69.5 or v0.69.6. Check self-hosted runners and developer machines for ~/.config/systemd/user/sysmon.py. Search network logs for scan.aquasecurtiy.org.
If any run used a bad version, rotate every secret that run held: GitHub tokens, cloud keys, registry credentials, SSH keys and database passwords. Then pin actions to full commit SHAs. A tag can move. A commit SHA cannot. Microsoft advises ephemeral runners and minimal token scope. Snyk advises repository-scoped tokens, a review of every pull_request_target workflow, and checks on outbound connections from CI.
How TeamPCP moved from Trivy to LiteLLM
TeamPCP used secrets stolen through Trivy to reach other projects. LiteLLM is the best-known case. LiteLLM ran Trivy in its CI pipeline without a pinned version. According to Snyk, the compromised action took the PYPI_PUBLISH token from the runner. On 24 March 2026 the attacker used it to publish litellm 1.82.7 and 1.82.8 to PyPI.
Endor Labs places the Trivy and LiteLLM events in one campaign across five ecosystems in about a month. It lists the Trivy compromise on 19 March, more than 45 npm packages on 20 March, Checkmarx KICS and OpenVSX extensions on 23 March, and LiteLLM on 24 March. The same command domain, checkmarx.zone, and the same tpcp.tar.gz archive name link the events.
The lesson for CI owners is direct. A security tool in your pipeline holds the same secrets as your build. If its tag moves, those secrets move with it. Read the full LiteLLM page for what the second stage stole. For an earlier npm case with the same pattern of a stolen publisher account, see the axios attack.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 9 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED action.yml It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
What is Trivy vulnerability?
Trivy is an open-source vulnerability scanner from Aqua Security. The Trivy vulnerability in the news is CVE-2026-33634, a critical (CVSS 9.4) supply chain compromise of March 2026. Attackers used stolen credentials to publish a malicious v0.69.4 release and to move tags in trivy-action and setup-trivy. It is not a bug in how Trivy scans.
Is Trivy still compromised?
No. Aqua Security removed the malicious components, and clean versions exist: Trivy v0.69.2 and v0.69.3, trivy-action v0.35.0 and setup-trivy v0.2.6. Copies can remain in caches. Any workflow that ran a bad version on 19 or 20 March 2026 must rotate its secrets.
Which Trivy versions were compromised?
Trivy v0.69.4 was the malicious release. Docker Hub images v0.69.5 and v0.69.6 were also bad. In trivy-action, 76 of 77 tags moved to malicious commits, and all 7 setup-trivy tags moved too.
How do I know if my pipeline ran the compromised Trivy?
Search your workflows for aquasecurity/trivy-action and aquasecurity/setup-trivy by tag. Review runs from 19 and 20 March 2026. Search your GitHub organization for repositories named tpcp-docs and your network logs for scan.aquasecurtiy.org.
Who was behind the Trivy attack?
A group that calls itself TeamPCP. The same group is linked to the later LiteLLM PyPI compromise, the Checkmarx KICS compromise and other attacks in March 2026.
Sources
- github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23
- github.com/advisories/GHSA-69fq-xp46-6x23
- wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack
- snyk.io/articles/trivy-github-actions-supply-chain-compromise/
- microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/
- snyk.io/blog/poisoned-security-scanner-backdooring-litellm/
- endorlabs.com/learn/teampcp-isnt-done
More supply chain attacks
- tj-actions/changed-files GitHub Action compromise 14 Mar 2025
- reviewdog/action-setup compromise 11 Mar 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.