Aqua Security·Technology / SaaS·
A privileged access token was extracted.
SecurityWeek reports maintainer-confirmed compromise of Trivy packages and related actions, with malware designed to steal credentials and other secrets. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: incomplete credential rotation
- Consequence
- Confirmed: A privileged access token was extracted.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Aqua Security
- Industry
- Technology / SaaS
- Disclosed
- Entry path
- Misconfiguration Exposure
- Affected asset
- repository automation and release processes
- Product / vendor
- Trivy
- Data involved
- Credentials · Authentication tokens
- Documented impact
- Data exposure
- Attached evidence
- 7 independent domains · 7 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved misconfiguration exposure.
ConfidencePrimaryExact excerpt
E1“Attackers exploited a misconfiguration in Trivy’s GitHub Actions environment, extracting a privileged access token and establishing a foothold”
aquasec.com · Apr 01 - 02
Reported cause
incomplete credential rotation
ConfidencePrimaryExact excerpt
E2“the rotation was not fully comprehensive”
aquasec.com · Apr 01 - 03
Affected product
Trivy
ConfidencePrimaryExact excerpt
E3“publish malicious releases of Trivy version 0.69.4”
aquasec.com · Apr 01 - 04
Reached
repository automation and release processes
ConfidencePrimaryExact excerpt
E4“establishing a foothold in repository automation and release processes”
aquasec.com · Apr 01 - 05
Observed
A privileged access token was extracted.
ConfidenceConfirmedExact excerpt
E5“extracting a privileged access token”
aquasec.com · Apr 01
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Not publicly established
No qualifying public evidence in the attached record.
- Downstream customer impact is not established in this incident record
- That a Defence review would have prevented this incident
4)Relevance to your product
A control left open in production can expose more than the product interface suggests.
This pattern applies when…
- Products that ingest third-party packages or security tooling into CI/CD.
- Teams that test repository permissions, token scope, credential rotation, and release integrity.
Diagnostic questions
- Does a public surface expose configuration that should remain internal?
- Can a production secret or administrative path be reached from the web?
- Do environment boundaries hold across current and legacy routes?
This incident does not establish your product's risk.
5)Sector context — Technology / SaaS
- 2 incident threads
- 1 incident threads
- 5 incident threads
- 2 incident threads
- 13 incident threads
- 5 incident threads
- 18 incident threads
- 16 incident threads
- 16 incident threads
- 16 incident threads
- 7 incident threads
- 29 incident threads
- Same incident family
- 56 Supply chain / third party
- Confirmed share
- 40% 52 confirmed · 78 reported
- Display family
- Supply chain Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Technology / SaaS in Radar →6)Defence control mapping
What Defence can test
Configuration and exposure review
- Does a public surface expose configuration that should remain internal?
- Can a production secret or administrative path be reached from the web?
- Do environment boundaries hold across current and legacy routes?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
7 attached sources across 7 independent domains. At least one primary source is attached.
- E1, E2, E3, E4, E5aquasec.comUpdate: Ongoing Investigation and Continued RemediationOrganization statement · Apr 01 · PrimaryOrganization statementPrimary
Exact excerpt
“extracting a privileged access token”
- S5microsoft.comGuidance for detecting, investigating, and defending against the Trivy supply chain compromise | Microsoft Security BlogSecurity research · Mar 25 · AttachedSecurity researchAttached
Exact excerpt
“credential harvesting phase”
Does this external exposure exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.