Trivy GitHub Action + Docker images compromised - start of TeamPCP cascade
Aqua Security's Trivy scanner was compromised on 19 March 2026 by the threat actor self-identifying as TeamPCP. The attacker force-pushed 76 of 77 tags in aquasecurity/trivy-action (only @0.35.0 survived) and all 7 tags in aquasecurity/setup-trivy to malicious commits, then published trojanised Trivy binary 0.69.4 + Docker images 0.69.5/0.69.6/latest. A stolen Argon-DevOps-Mgt service-account token seeded the downstream LiteLLM, Telnyx, Bitwarden CLI, and Checkmarx compromises.
Versions named here: 0.69.4, 0.69.5, 0.69.6, latest