Country visual unavailable
No information
On 19 March 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, replace Trivy GitHub Action tags with credential-stealing malware and distribute compromised artifacts through trusted release channels; additional malicious Docker Hub images followed on 22 March. Aqua's incident analysis linked the access to incomplete credential rotation after an earlier compromise. The poisoned Trivy supply chain subsequently provided a credential-theft path into other software vendors, including Checkmarx and BerriAI's LiteLLM, creating a documented downstream software-supply-chain propagation.
Estimated severity
82 / 100
Source reliability
93 / 100
Approximate Date
19/03/2026
Targeted Company
AQUA SECURITY
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone