BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Trivy Attack Escalates: Malicious Docker Images Found

TeamPCP sabotages Trivy vulnerability scanner on Docker Hub to spread infostealer and wiper malware.

  • Threat actor TeamPCP has distributed malicious versions of the Trivy vulnerability scanner on Docker Hub, with versions 0.69.4, 0.69.5, and 0.69.6 containing an infostealer.
  • The supply chain attack compromised internal repositories at Aqua Security, defacing them with “TeamPCP Owns Aqua Security” messages and exposing proprietary code.
  • The attackers have escalated their campaign using stolen credentials to deploy a wiper malware targeting Iranian Kubernetes clusters and a self-propagating worm called CanisterWorm.
  • The last known clean release of the Trivy Docker image is 0.69.3, and organizations are urged to review their CI/CD pipelines for use of compromised versions.

Following a major supply chain compromise, cybersecurity researchers discovered malicious Docker images for the Trivy vulnerability scanner on Docker Hub, where threat actors posted Trojanized versions as recently as March 22, 2026. The attack, attributed to the group TeamPCP, originally involved a compromised credential to push a credential stealer within the open-source scanner and related GitHub Actions.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to a report from Socket security researcher Philipp Burckhardt, the malicious image tags 0.69.5 and 0.69.6 did not have corresponding GitHub releases. Consequently, the attack’s blast radius has expanded dramatically, with TeamPCP leveraging stolen data to compromise dozens of npm packages to distribute the CanisterWorm.

Meanwhile, the attackers have defaced all 44 internal repositories in Aqua Security‘s “aquasec-com” GitHub organization in a scripted two-minute burst. A forensic analysis by OpenSourceMalware assessed with high confidence that a compromised “Argon-DevOps-Mgt” service account token was the attack vector, providing write access to both of the security vendor’s GitHub organizations.

The campaign showcases the group’s growing sophistication, now moving beyond credential theft to destructive wiper malware. A new payload identified by researcher Charlie Eriksen targets Iranian Kubernetes nodes for wiping, while non-Iranian systems are infected with the CanisterWorm backdoor. This evolution highlights a significant threat to the security vendor ecosystem itself, turning its own tools against it.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Fidelity Urges SEC for Crypto Trading Rules on ATS

Fidelity Investments, an $18 trillion asset manager, urged the Securities and Exchange Commission (SEC)...

ZachXBT Uncovers Fake War Posts for Crypto Scams

Investigator ZachXBT uncovered a network of fake X accounts using AI-generated war and political...

Iran Pressures BRICS to Mediate in US-Israel Conflict, Strains India

Iran has urged BRICS to take an "independent role" in mediating the Iran-US-Israel conflict,...

SMCI Stock Plunges Amid Nvidia China Probe

Super Micro Computer Inc. (SMCI) shares plummeted 33% in a single session, erasing over...

Bithumb to Reappoint CEO Amid Regulatory Scrutiny

Bithumb is seeking to reappoint CEO Lee Jae-won for another two-year term despite recent...

Must Read

Top 9 Most Legit Bitcoin Faucets

Bitcoin faucets are platforms where you can earn Bitcoin free. Some other faucet apps and websites allow users to receive different cryptocurrencies for free....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading