Trivy Hack Spreads Infostealer via Docker Triggers Worm and Kubernetes Wiper
After the Trivy supply chain hack, cybersecurity experts discovered malicious assets spread via Docker Hub, underscoring the expanding blast radius across developer environments.
Trivy's most recent clean release on Docker Hub is 0.69.3. Since then, the container image library has been cleared of the malicious versions 0.69.4, 0.69.5, and 0.69.6.
On March 22, new image tags 0.69.5 and 0.69.6 were pushed without matching GitHub releases or tags. According to Socket security researcher Philipp Burckhardt, both photos show signs of compromise connected to the same TeamPCP infostealer seen in earlier phases of this campaign.
The development follows a supply chain breach of Trivy, a well-known open-source vulnerability scanner run by Aqua Security, which gave threat actors the ability...

