DEFENCE / RADAR

Public snapshot

Aqua Security·Technology / SaaS·

A privileged access token was extracted.

SecurityWeek reports maintainer-confirmed compromise of Trivy packages and related actions, with malware designed to steal credentials and other secrets. The attached record does not establish the complete downstream scope.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: incomplete credential rotation
Consequence
Confirmed: A privileged access token was extracted.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Aqua Security
Industry
Technology / SaaS
Disclosed
Entry path
Misconfiguration Exposure
Affected asset
repository automation and release processes
Product / vendor
Trivy
Data involved
Credentials · Authentication tokens
Documented impact
Data exposure
Attached evidence
7 independent domains · 7 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved misconfiguration exposure.

    ConfidencePrimary
    Exact excerpt

    Attackers exploited a misconfiguration in Trivy’s GitHub Actions environment, extracting a privileged access token and establishing a foothold

    aquasec.com · Apr 01
    E1
  2. 02

    Reported cause

    incomplete credential rotation

    ConfidencePrimary
    Exact excerpt

    the rotation was not fully comprehensive

    aquasec.com · Apr 01
    E2
  3. 03

    Affected product

    Trivy

    ConfidencePrimary
    Exact excerpt

    publish malicious releases of Trivy version 0.69.4

    aquasec.com · Apr 01
    E3
  4. 04

    Reached

    repository automation and release processes

    ConfidencePrimary
    Exact excerpt

    establishing a foothold in repository automation and release processes

    aquasec.com · Apr 01
    E4
  5. 05

    Observed

    A privileged access token was extracted.

    ConfidenceConfirmed
    Exact excerpt

    extracting a privileged access token

    aquasec.com · Apr 01
    E5

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • Downstream customer impact is not established in this incident record
  • That a Defence review would have prevented this incident

4)Relevance to your product

A control left open in production can expose more than the product interface suggests.

This pattern applies when…

  • Products that ingest third-party packages or security tooling into CI/CD.
  • Teams that test repository permissions, token scope, credential rotation, and release integrity.

Diagnostic questions

  1. Does a public surface expose configuration that should remain internal?
  2. Can a production secret or administrative path be reached from the web?
  3. Do environment boundaries hold across current and legacy routes?

This incident does not establish your product's risk.

5)Sector context — Technology / SaaS

130 incident threads in the 365-day public record
  1. 2 incident threads
  2. 1 incident threads
  3. 5 incident threads
  4. 2 incident threads
  5. 13 incident threads
  6. 5 incident threads
  7. 18 incident threads
  8. 16 incident threads
  9. 16 incident threads
  10. 16 incident threads
  11. 7 incident threads
  12. 29 incident threads
Same incident family
56
Supply chain / third party
Confirmed share
40%
52 confirmed · 78 reported
Display family
Supply chain
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Technology / SaaS in Radar →

6)Defence control mapping

What Defence can test

Configuration and exposure review

  • Does a public surface expose configuration that should remain internal?
  • Can a production secret or administrative path be reached from the web?
  • Do environment boundaries hold across current and legacy routes?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

7 attached sources across 7 independent domains. At least one primary source is attached.

  1. E1, E2, E3, E4, E5
    aquasec.comUpdate: Ongoing Investigation and Continued RemediationOrganization statement · Apr 01 · Primary
    Organization statementPrimary
    Exact excerpt
    extracting a privileged access token
  2. S2
    arstechnica.comWidely used Trivy scanner compromised in ongoing supply-chain attack - Ars TechnicaEstablished press · Mar 20 · Attached
    Established pressAttached
  3. S3
    securityweek.comAqua's Trivy Vulnerability Scanner Hit by Supply Chain Attack - SecurityWeekEstablished press · Mar 23 · Attached
    Established pressAttached
  4. S4
    secnews.grTrivy Breach: Malicious Software Steals CI/CD SecretsOther public report · Mar 23 · Attached
    Other public reportAttached
  5. S5
    microsoft.comGuidance for detecting, investigating, and defending against the Trivy supply chain compromise | Microsoft Security BlogSecurity research · Mar 25 · Attached
    Security researchAttached
    Exact excerpt
    credential harvesting phase
  6. S6
    securityaffairs.comU.S. CISA adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalogSpecialist reporting · Mar 27 · Attached
    Specialist reportingAttached
Show all 7 sourcesShow the first six sources
  1. S7
    unit42.paloaltonetworks.comWeaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security InfrastructureSecurity research · Mar 31 · Attached
    Security researchAttached

Does this external exposure exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →