216.73.217.80

Guidance for detecting, investigating, and defending against the Trivy supply chain compromise

· Published 25/03/2026 04:25 · Modified 27/03/2026 00:08

Export JSON

Essential information

Published
25/03/2026 04:25
Modified
27/03/2026 00:08
Tags
2026-03-25 credential-theft supply chain attack trivy
Related entities
2 observables, 1 intrusion sets (apt), 9 techniques (mitre), 1 malware, 5 others

Description

On March 19, 2026, , an open-source vulnerability scanner, was compromised in a sophisticated CI/CD . Threat actors, identified as TeamPCP, injected credential-stealing malware into official releases, affecting the core binary and GitHub Actions. The attack exploited mutable tags and commit identity spoofing on GitHub. The malware performed extensive credential harvesting, targeting cloud providers, Kubernetes secrets, and various application credentials. Microsoft Defender provides detection and investigation capabilities for this threat. Recommended mitigations include updating to safe versions, hardening CI/CD pipelines, enforcing least privilege, protecting secrets, and leveraging attack path analysis to reduce lateral movement risks.

External references