[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH61rIG9pBt4B2dDarHHyNIQvHXi6A5fQzu75E0Ge6JE":3},{"article":4,"iocs":38,"watch_terms":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"53e68da5-432b-46ac-a3d3-2624ef1a9da5","Trivy Supply Chain Attack Targets CI\u002FCD Secrets","trivy-supply-chain-attack-targets-ci-cd-secrets","A threat actor used the open source security tool to deploy an infostealer into CI\u002FCD workflows and steal cloud credentials, SSH keys, tokens, and other sensitive secrets.","A threat actor compromised the Trivy security scanning tool to inject an infostealer that targets CI\u002FCD workflows, exfiltrating cloud credentials, SSH keys, API tokens, and other sensitive secrets. The attack leverages trust in the widely-used open-source project to gain access to development infrastructure and authentication material. This represents a significant supply chain risk to organizations relying on Trivy for container and artifact scanning.","Trivy open-source tool compromised to steal CI\u002FCD secrets and cloud credentials.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fapplication-security\u002Ftrivy-supply-chain-attack-targets-ci-cd-secrets","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt56a20b542c082472\u002F69c1a720f5bbfd6de1b8a688\u002Fsupplychain_ImageFlow_shutterstock.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-03-23T21:43:59+00:00","2026-03-23T23:00:15.729433+00:00",9,[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":18,"icon":11,"name":20,"slug":21},"Supply Chain","supply-chain",[23,28,33],{"category":24},{"id":25,"icon":11,"name":26,"slug":27},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[39],{"type":27,"value":40,"context":41},"Trivy infostealer","Malicious payload injected into Trivy open-source security tool to steal CI\u002FCD secrets",[]]