Trivy Supply Chain Attack Spreads Through Compromised Docker Hub Images

The cybersecurity world is facing a severe supply chain attack that is growing in scale. Following a recently discovered breach involving the aquasecurity/trivy-action repository on GitHub, threat researchers at Socket have uncovered a dangerous escalation.

Malicious actors have now successfully published compromised Trivy software directly to Docker Hub. This new development puts countless organizations at major risk, as Trivy is a highly popular open-source security scanner used by developers to find vulnerabilities in automated pipelines.

Tracking The Compromised Versions and Malware

The attack moved to a new phase on March 22 when hackers pushed two new software image tags to Docker Hub.

These new tags, labeled 0.69.5 and 0.69.6, appeared silently, with no matching official releases on GitHub. Even more alarming, the standard “latest” tag on Docker Hub currently directs users to version 0.69.6.

Security analysts examined the malicious files and confirmed they contain the same malicious code observed earlier in this attack.

Trivy Attack Hits DockerHub (Source: socket)
Trivy Attack Hits DockerHub (Source: socket)

The primary threat is the TeamPCP infostealer. This type of malware is designed to quietly infiltrate systems and steal sensitive information, such as passwords, security tokens, and API keys.

The attackers purposely misspelled the domain to look like a legitimate Aqua Security web address.

Researchers also identified stolen data files named payload.enc and tpcp.tar.gz, along with hidden code pointing to a backup GitHub repository called tpcp-docs.

Trivy Attack Hits DockerHub (Source: socket)
Trivy Attack Hits DockerHub (Source: socket)

To help security teams navigate this incident, here is a clear breakdown of the recently affected Trivy versions:

VersionCurrent StatusTechnical Details
0.69.3SafeThis remains the last known clean and safe release.
0.69.4CompromisedThe initial malicious release, which has since been removed.
0.69.5CompromisedA newly identified malicious Docker image pushed directly by attackers.
0.69.6CompromisedThe current “latest” malicious Docker image active on the platform.

Broader Impact and Immediate Security Measures

The full scope of this incident might be much larger than originally expected. Security researcher Paul McCarty noted that the main Aqua Security GitHub organization appeared to be exposed during the attack.

This alarming detail suggests the hackers have temporarily made internal private repositories visible to the public. While the exact details of this exposure are still under investigation, it clearly shows the deep level of system access the attackers achieved.

According to socket research, a quick search for Trivy on Docker Hub reveals thousands of related software images. These include official builds, continuous integration tools, and numerous customized versions made by external developers.

While these third-party images are not compromised by default, they carry a hidden risk.

Any system that automatically downloaded or rebuilt itself using the affected Trivy versions during the attack window might now contain the malicious code. This creates a dangerous ripple effect across the software supply chain.

Every organization using Trivy must review its development pipelines right away. Security teams need to avoid the affected versions entirely and treat any recent automated scans as potentially breached.

By acting quickly, companies can stop the TeamPCP infostealer from compromising their valuable internal data.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories