[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbS8cN7inJKdr9Lh-hxm0QHr_Jjv9prvUYWKsauKpP7M":3},{"article":4,"iocs":34,"watch_terms":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":23},"85587bcf-1315-487d-afca-ca71ca26ba6b","Guidance for detecting, investigating, and defending against the Trivy supply chain compromise","guidance-for-detecting-investigating-and-defending-against-the-trivy-supply-chai","Threat actors abused trusted Trivy distribution channels to inject credential‑stealing malware into CI\u002FCD pipelines worldwide. This analysis walks through the Trivy supply‑chain compromise, attacker techniques, and concrete steps security teams can take to detect and defend against similar attacks. The post Guidance for detecting, investigating, and defending against the Trivy supply chain compromise appeared first on Microsoft Security Blog.","On March 19, 2026, threat actor TeamPCP exploited prior unpatched access to poison Trivy's distribution channels, injecting credential-stealing malware into the core scanner binary and associated GitHub Actions. The attack simultaneously compromised trivy-action and setup-trivy, forcing 76+ version tags to malicious commits that harvested cloud credentials, Kubernetes secrets, CI\u002FCD tokens, and SSH keys from downstream workflows. The campaign expanded to additional frameworks including Checkmarx KICS and LiteLLM.","Trivy vulnerability scanner compromised to inject credential-stealing malware into CI\u002FCD pipelines worldwide.","Share Link copied to clipboard! Content types Research Products and services Microsoft Defender Topics Actionable threat insightsDefending against advanced tactics On March 19, 2026, Trivy, Aqua Security’s widely used open-source vulnerability scanner, was reported to have been compromised in a sophisticated CI\u002FCD-focused supply chain attack. Threat actors leveraged access from a prior incident that was not fully remediated to inject credential-stealing malware into official releases of Aqua Security’s widely adopted open-source vulnerability scanner, Trivy. The attack simultaneously compromised the core scanner binary, the trivy-action GitHub Action, and the setup-trivy GitHub Action, weaponizing trusted security tooling against the organizations relying on it. The campaign, attributed to the threat actor identifying as TeamPCP, introduces several concerning techniques. This blog walks through the Trivy supply chain attack and explains how Microsoft Defender helps organizations detect, investigate, and respond to this incident. This activity has since expanded to additional frameworks, including Checkmarx KICS and LiteLLM, with further details to be shared as the investigation continues. Analyzing the Trivy supply chain compromise The activity on March 19 represents the execution phase of the campaign, where previously established access was used to weaponize trusted Trivy distribution channels: Poisoning GitHub Actions used in CI\u002FCD pipelines: Using compromised credentials with tag write access, the attacker force-pushed 76 of 77 version tags in aquasecurity\u002Ftrivy-action and all 7 tags in aquasecurity\u002Fsetup-trivy, redirecting existing, trusted version references to malicious commits. This caused downstream workflows to execute attacker-controlled code without any visible change to release metadata. Publishing a malicious Trivy binary: In parallel, the attacker triggered release automation to publish an infected Trivy binary (v0.69.4) to official distribution channels, including GitHub Releases and container registries, exposing both CI\u002FCD environments and developer machines to credential theft and persistence. Maintaining stealth and impact window: Both the compromised GitHub Actions and the malicious binary were designed to execute credential-harvesting logic in addition to the legitimate Trivy functionality, allowing workflows and scans to appear successful while secrets were exfiltrated. Attack containment by maintainers: Later that day, the Trivy team identified the compromise and removed malicious artifacts from distribution channels, ending the active propagation phase. How GitHub’s design was abused in the attack This attack exploited two aspects of how Git and GitHub operate by design: mutable tags and self-declared commit identity, turning expected platform behavior into an advantage for the attacker. In Git, a tag is a label that maps to a specific commit in the repository’s history. By default, these references are not immutable – anyone with push access can reassign an existing tag to point to an entirely different commit. The attacker did exactly that, replacing the target commit behind 76 of 77 tags in trivy-action and all 7 in setup-trivy with commits containing malicious payloads. Every CI\u002FCD pipeline that referenced these actions by tag name began running the attacker’s code on its next execution, with no visible change on GitHub to alert maintainers or consumers. In addition, the threat actor spoofed the identity of the commit, similar to the persona impersonation tactics seen in the Shai-Hulud 2.0 campaign. Exploitation details Microsoft Defender for Cloud observed the full attack chain in compromised self-hosted GitHub Actions runners. Upon execution, the entry point performed process discovery to locate runner processes (Runner.Worker, Runner.Listener), then inspected them to identify processes carrying secrets. A base64-encoded Python payload was then decoded and executed to handle the credential harvesting phase. The Python stealer first fingerprinted the host (“hostname”, “whoami”, “uname -a”, “ip addr”) and dumped all environment variables (via “printenv”). It then conducted broad-spectrum credential harvesting that reveals the attacker’s interest in maximizing the value of each compromised runner: Cloud credentials: For each major cloud provider, the stealer combined environment variable extraction with deeper credential access attempts:AWS: Harvested environment variables (“grep AWS_”), then queried both the ECS task metadata endpoint (169.254.170.2) and the EC2 instance metadata service (169.254.169.254) for IAM credentials.GCP: Harvested environment variables (“grep -i google”, “grep -i gcloud”) and attempted to read the service account key file via $GOOGLE_APPLICATION_CREDENTIALS. Azure: Harvested environment variables (“grep -i azure”). Kubernetes secrets: Enumeration and exfiltration of mounted service-account files (under “\u002Frun\u002Fsecrets\u002Fkubernetes.io\u002Fserviceaccount\u002F”), and an attempt to dump all cluster secrets with Kubernetes CLI (“kubectl get secrets –all-namespaces -o json”). CI\u002FCD and application secrets: Reading the runner’s internal environment files, recursive filesystem searches for API keys and tokens in “.env”, “.json”, “.yml”, and “.yaml” files, and harvesting of Slack and Discord webhook URLs. Infrastructure and access: Extraction of WireGuard VPN configurations (“wg showconf all”), SSH authentication logs (“\u002Fvar\u002Flog\u002Fauth.log”, “\u002Fvar\u002Flog\u002Fsecure”), and database connection strings (MySQL, PostgreSQL, MongoDB, Redis, Vault). Cryptocurrency: Searches for Solana wallet variables and RPC authentication credentials (rpcuser, rpcpassword). The stolen data was then encrypted using a hybrid AES-256-CBC + RSA scheme and bundled into a tpcp.tar.gz archive, then exfiltrated via HTTP POST to the typosquatted domain scan.aquasecurtiy[.]org. After exfiltration, the malware cleaned up all temporary files and launched the legitimate Trivy scan. The workflow completed successfully with expected output, masking the compromise from pipeline operators. Detection and investigation Microsoft Defender XDR customers can refer to the list of applicable detections below. Microsoft Defender XDR coordinates detection, prevention, investigation, and response across endpoints, identities, email, and apps to provide integrated protection against attacks like the threat discussed in this blog. Customers with provisioned access can also use Microsoft Security Copilot in Microsoft Defender to investigate and respond to incidents, hunt for threats, and protect their organization with relevant threat intelligence. TacticObserved activityMicrosoft Defender coverageCredential accessAccess to the IMDS endpoint in cloud resources to steal cloud tokensMicrosoft Defender for Cloud:– Access to cloud metadata service detectedCredential accessSecret Reconnaissance on containers served as CI\\CD runnersMicrosoft Defender for Cloud:– Possible Secret Reconnaissance Detected Microsoft Defender for Endpoint: – Kubernetes Secrets Enumeration Indicative of Credential Access Command and ControlDNS query to a domain name which is identified as suspicious by Microsoft Threat Intelligence – including the scan[.]aquasecurtiy[.]org domain (and others)Microsoft Defender for Identity:– Suspicious DNS query from a device in the organizationMicrosoft Defender for Endpoint: – Suspicious connection blocked by network protection – Suspicious activity linked to an emerging threat actor has been detected – Connection to a custom network indicator ExfiltrationMalicious exfiltration activity performed by infected Trivy versionMicrosoft Defender for Cloud:– Malicious commands from TeamPCP supply chain attack detectedMicrosoft Defender for Endpoint: – Possible data exfiltration using curl Mitigation and protection guidance The recent compromise affecting Trivy and related GitHub Actions highlights how attackers increasingly target CI\u002FCD pipelines, trusted developer tooling an","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F03\u002F24\u002Fdetecting-investigating-defending-against-trivy-supply-chain-compromise\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F03\u002FMS_Actional-Insights_Malware-ransomware-1.jpg","2026-03-25T00:03:03+00:00","2026-03-25T03:00:04.92565+00:00",9,[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":18,"icon":20,"name":21,"slug":22},null,"Supply Chain","supply-chain",[24,29],{"category":25},{"id":26,"icon":20,"name":27,"slug":28},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":30},{"id":31,"icon":20,"name":32,"slug":33},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[35,39,42,45,49],{"type":36,"value":37,"context":38},"domain","scan.aquasecurtiy.org","Typosquatted exfiltration domain used by malware to steal credentials",{"type":28,"value":40,"context":41},"TeamPCP","Threat actor responsible for Trivy supply chain compromise",{"type":28,"value":43,"context":44},"tpcp.tar.gz","Archive filename containing encrypted stolen credentials",{"type":46,"value":47,"context":48},"ip","169.254.170.2","ECS task metadata endpoint targeted for AWS credential harvesting",{"type":46,"value":50,"context":51},"169.254.169.254","EC2 instance metadata service targeted for IAM credential theft",[]]