Guidance for detecting, investigating, and defending against the Trivy supply chain compromise

Reported 25 Mar 2026 by otx · Severity: medium

On March 19, 2026, Trivy, an open-source vulnerability scanner, was compromised in a sophisticated CI/CD supply chain attack. Threat actors, identified as TeamPCP, injected credential-stealing malware into official Trivy releases, affecting the core binary and GitHub Actions. The