A significant breach has affected Aqua Security's Trivy vulnerability scanner, which is extensively utilized by developers. This incident was confirmed by maintainer Itay Shakury, following the emergence of rumors and a now-deleted discussion thread initiated by the attackers. The compromise occurred early Thursday, where the threat actor exploited stolen credentials to execute a forced push, altering nearly all versions of the scanner. This included modifying all but one of the trivy-action tags and seven setup-trivy tags to incorporate harmful dependencies. Developers rely on Trivy to identify vulnerabilities and detect hardcoded authentication secrets within their software development pipelines. With over 33,200 stars on GitHub, Trivy is recognized as a crucial tool in the software development community. The implications of this breach could be severe, leading to potential risks for organizations that utilize this scanner in their workflows. Users are advised to assume their pipelines may have been compromised and take necessary precautions.
Trivy Vulnerability Scanner Compromised in Supply Chain Attack
Aqua Security's Trivy scanner, essential for developers, has been compromised in a significant supply chain attack, raising alarms for users.
