HomeSecurityGitHub Actions Breach of Trivy Security Scanner

Violation of GitHub Actions of the Trivy Security Scanner

Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was hacked for the second time in a month to distribute malware that stole sensitive CI/CD secrets.

See also: GhostClaw: Malware for macOS via GitHub

Trivia

The latest incident affected the GitHub Actions “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,” which are used to scan Docker container images for vulnerabilities and to configure the GitHub Actions workflow with a specific version of the scanner, respectively.

“ We discovered that an attacker force-pushed 75 out of 76 release tags in the aquasecurity/trivy-action repository, the official GitHub Action for running Trivy vulnerability scans in CI/CD pipelines ,” said Socket security researcher Philipp Burckhardt . “ These tags were modified to serve a malicious payload, essentially turning trusted release reports into a distribution mechanism for an infostealer. ”

The payload runs inside the GitHub Actions runners and aims to exfiltrate valuable developer secrets from CI/CD environments, such as SSH keys, credentials for cloud service providers, databases, Git, Docker configurations, Kubernetes tokens, and cryptocurrency wallets.

This development marks the second supply chain incident involving Trivy. In late February and early March 2026, a standalone bot called hackerbot-claw exploited a “ pull_request_target ” workflow to steal a Personal Access Token (PAT), which was then used to seize control of the GitHub repository, delete several release builds, and push two malicious versions of the Visual Studio Code (VS Code) extension to Open VSX .

See also: GlassWorm attack: Stolen GitHub tokens used to insert malware into Python repos

Violation of GitHub Actions of the Trivy Security Scanner

The first sign of the breach was spotted by security researcher Paul McCarty after a new compromised version ( version 0.69.4 ) was posted to the GitHub repository “ aquasecurity/trivy .” The malicious version has now been removed. According to Wiz, version 0.69.4 launches both the legitimate Trivy service and malicious code that is responsible for a number of tasks:

  • Conducting data theft by scanning the system for environment variables and credentials, encrypting the data and exfiltrating it via an HTTP POST request to scan.aquasecurtiy[.]org.
  • Setting persistence using a systemd service after confirming it runs on a developer machine. The systemd service is configured to run a Python script (“sysmon.py”) that looks for an external server to retrieve the payload and execute it.

In a statement, Itay Shakury, vice president of open source at Aqua Security, said the attackers exploited a compromised credential to publish malicious versions of Trivy, trivy-action and setup-trivy. In the case of “aquasecurity/trivy-action,” the adversary force-pushed 75 version tags to point to malicious commits containing the Python infostealer payload without creating a new version, as is standard practice. Seven “aquasecurity/setup-trivy” tags were force-pushed in the same way.

The security vendor also acknowledged that the latest attack stemmed from the lack of containment of the hackerbot-claw incident. “We rotated secrets and tokens, but the process was not individual and the attackers may have had access to renewed tokens,” Shakury said. “We are now taking a more restrictive approach and locking down all automated actions and any tokens to completely eliminate the problem.”

See also: Nvidia turns OpenClaw into NemoClaw enterprise platform

Violation of GitHub Actions of the Trivy Security Scanner

The stealer operates in three stages: collecting environment variables from the memory of the runner process and the file system, encrypting the data and exfiltrating it to the server controlled by the attacker (“scan.aquasecurtiy[.]org”).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS