MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Aqua Security Trivy supply-chain compromise distributes credential-stealing releases

On 19 March 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, replace Trivy GitHub Action tags with credential-stealing malware and distribute compromised artifacts through trusted release channels; additional malicious Docker Hub images followed on 22 March. Aqua's incident analysis linked the access to incomplete credential rotation after an earlier compromise. The poisoned Trivy supply chain subsequently provided a credential-theft path into other software vendors, including Checkmarx and BerriAI's LiteLLM, creating a documented downstream software-supply-chain propagation.

82

Estimated severity

82 / 100

93

Source reliability

93 / 100

Approximate Date

19/03/2026

Targeted Company

AQUA SECURITY

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

CHECKMARX (Software vendor)BERRIAI (Software vendor)

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impactDownstream customer disruption

Affected sectors

Technology & IT Services

Affected departments

Information TechnologyEngineering & Maintenance

Attack Profile

Attack types

Use of stolen credentialsUnauthorized accessSoftware supply chain compromiseMalwareData exfiltration

Attributed threat actors

TEAMPCP

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.