<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — Trivy</title>
  <link>https://appsec.fyi/tools.html#trivy</link>
  <description>Curated Trivy resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/tool/trivy.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Sun, 06 Sep 2026 16:03:59 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack</title>
    <link>https://wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack</link>
    <guid isPermaLink="true">https://wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack</guid>
    <description>Library. This entry details the &quot;TeamPCP&quot; supply chain attack that compromised Aqua Security&#x27;s Trivy vulnerability scanner and related GitHub Actions. The attack involved injecting credential-stealing malware into official releases and workflows, leading to the exfiltration of secrets via typosquatted domains and fallback repository mechanisms. Threat actors also leveraged stolen publish tokens for npm ecosystem compromise and deployed iterative payloads. Organizations should audit Trivy versions and GitHub Action references, and consider pinning actions to full SHA hashes for long-term hardening.</description>
    <category domain="tool">Trivy</category>
    <category domain="difficulty">news</category>
    <pubDate>Wed, 10 Jun 2026 06:01:37 +0000</pubDate>
  </item>
  <item>
    <title>How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM</title>
    <link>https://snyk.io/blog/poisoned-security-scanner-backdooring-litellm</link>
    <guid isPermaLink="true">https://snyk.io/blog/poisoned-security-scanner-backdooring-litellm</guid>
    <description>Library containing a backdoor that exploited Trivy security scanner vulnerabilities to compromise LiteLLM Python packages, specifically versions 1.82.7 and 1.82.8. The malicious code was delivered via direct source injection or a `.pth` file, leading to credential theft, data exfiltration using AES-256 and RSA encryption, and persistence through systemd services and Kubernetes lateral movement. This attack chain is linked to the threat actor TeamPCP, identified by consistent infrastructure and an RSA public key shared with prior Trivy and KICS compromises.</description>
    <category domain="tool">Trivy</category>
    <category domain="difficulty">news</category>
    <pubDate>Tue, 09 Jun 2026 06:00:55 +0000</pubDate>
  </item>
  <item>
    <title>We hardened zizmor&#x27;s GitHub Actions static analyzer</title>
    <link>https://blog.trailofbits.com/2026/05/22/we-hardened-zizmors-github-actions-static-analyzer</link>
    <guid isPermaLink="true">https://blog.trailofbits.com/2026/05/22/we-hardened-zizmors-github-actions-static-analyzer</guid>
    <description>Library that hardened zizmor, a static analyzer for GitHub Actions workflows, by fixing parsing bugs related to YAML anchors and surfacing deserialization edge cases. This work addressed issues like malformed findings and silent data mishandling, improving zizmor&#x27;s analysis of workflows from 6,612 high-value open-source repositories and aligning its expression evaluator with GitHub&#x27;s test suite. The improvements enhance protection against supply-chain attacks, such as the aquasecurity/trivy-action exploit.</description>
    <category domain="tool">Trivy</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Mon, 08 Jun 2026 02:51:17 +0000</pubDate>
  </item>
  <item>
    <title>Trivy Supply-Chain Attack: Trusted Scanner Compromised Rotate CI/CD Secrets Now</title>
    <link>https://www.intelligentliving.co/trivy-trusted-scanner-compromised-cicd/</link>
    <guid isPermaLink="true">https://www.intelligentliving.co/trivy-trusted-scanner-compromised-cicd/</guid>
    <description>Library for securing CI/CD pipelines against supply-chain attacks, particularly concerning the Trivy scanner compromise (CVE-2026-33634, GHSA-69fq-xp46-6×23). The library details techniques for mitigating risks associated with compromised scanning tools, including mandatory secret rotation, auditing pipeline runs, pinning GitHub Actions tags to immutable SHAs, enforcing least-privilege for runners, and increasing monitoring. It highlights how attackers exploit tag mutability and privileged scanner access to steal credentials and access cloud environments.</description>
    <category domain="tool">Trivy</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 18 Apr 2026 09:30:46 +0000</pubDate>
  </item>
  <item>
    <title>European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack</title>
    <link>https://www.securityweek.com/european-commission-confirms-data-breach-linked-to-trivy-supply-chain-attack/</link>
    <guid isPermaLink="true">https://www.securityweek.com/european-commission-confirms-data-breach-linked-to-trivy-supply-chain-attack/</guid>
    <description>Writeup detailing the European Commission&#x27;s data breach, confirming over 300GB of data theft from its AWS environment. Hackers exploited an API key compromised during the TeamPCP-led supply chain attack on Aqua Security&#x27;s Trivy vulnerability scanner. The attackers leveraged tools like TruffleHog to discover secrets and exfiltrate data related to 71 clients of the Europa web hosting service, with the stolen information later appearing on the ShinyHunters leak site.</description>
    <category domain="tool">Trivy</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 04 Apr 2026 10:45:49 +0000</pubDate>
  </item>
  <item>
    <title>Open Source Security Tool Trivy Hit by Supply Chain Attack Prompting Urgent Industry Response</title>
    <link>https://www.infoq.com/news/2026/04/trivy-supply-chain-attack/</link>
    <guid isPermaLink="true">https://www.infoq.com/news/2026/04/trivy-supply-chain-attack/</guid>
    <description>Tool Trivy was compromised in a supply chain attack, with malicious release v0.69.4 briefly distributed, exfiltrating sensitive data and executing malicious code. Attackers leveraged compromised credentials and manipulated release processes, impacting downstream systems and related tooling like GitHub Actions. This incident highlights the vulnerability of trusted open source scanners and CI/CD pipelines, prompting calls for artifact integrity verification, credential scoping, and zero-trust principles in software supply chains.</description>
    <category domain="tool">Trivy</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 03 Apr 2026 12:15:55 +0000</pubDate>
  </item>
</channel>
</rss>