The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Trivy was compromised in two connected supply-chain attacks in March 2026, followed by a later Docker Hub image wave. Attackers used access to Trivy’s release and GitHub Actions infrastructure to distribute a malicious Trivy v0.69.4, hijack most aquasecurity/trivy-action tags, replace all aquasecurity/setup-trivy tags, and publish malicious images labeled v0.69.5 and v0.69.6.
Organizations that ran affected artifacts should treat secrets available to those runners as potentially exposed, investigate historical workflow runs—not only current YAML files—and rotate credentials after revoking the old ones.
What happened
Trivy is an open-source security scanner for container and repository vulnerabilities, misconfigurations, secrets, SBOMs, Kubernetes environments, and cloud workloads. It is commonly executed inside CI/CD jobs, where it may run alongside credentials such as GITHUB_TOKEN, cloud keys, registry passwords, signing keys, package-publishing tokens, SSH keys, and Kubernetes credentials.
That made the compromise more serious than a normal malicious release. The affected payload was designed to run in developer or CI environments, search for credentials and secrets, package collected data, and exfiltrate it. Investigators reported encrypted archives, HTTP POST exfiltration, and the typosquatted domain scan.aquasecurtiy[.]org. These were capabilities and observed indicators, not proof that every affected execution exfiltrated data.
#1 Best Overall
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
The official incident record is GHSA-69fq-xp46-6×23. Microsoft published additional technical analysis, and Aqua said there was no indication that its commercial products were affected; that statement should be understood as Aqua’s position, not an independent certification.
The timeline
Late February and March 1: the initial foothold
Attackers exploited a misconfiguration in Trivy’s GitHub Actions environment and obtained privileged access. Aqua disclosed the first incident on March 1, 2026. Credentials were rotated, but the rotation was not fully atomic: not every relevant credential was revoked and replaced simultaneously. That left a path for residual access and enabled the later compromise.
The official advisory establishes the connection between the incidents. More specific claims about the initial exploit or attacker attribution should be treated cautiously unless supported by the relevant investigation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
March 19–20: the second compromise
| Component | Exposure window, UTC | What was affected |
|---|---|---|
Trivy binary and images at v0.69.4 |
March 19, approximately 18:22–21:42 | Downloaded or executed affected releases |
aquasecurity/trivy-action |
March 19 approximately 17:43 through March 20 approximately 05:40 | Mutable tags were hijacked |
aquasecurity/setup-trivy |
March 19 approximately 17:43–21:44 | Tags were replaced with malicious commits |
The attacker published malicious Trivy v0.69.4, force-pushed 76 of 77 trivy-action version tags, and replaced all seven setup-trivy tags. The malicious artifacts were distributed through normal release channels, making them difficult to distinguish from legitimate tools without checking provenance.
March 22–23: the Docker Hub follow-on wave
The incident did not necessarily end on March 20. The advisory records malicious Docker Hub images labeled v0.69.5 and v0.69.6, exposed from approximately 15:43 UTC on March 22 until about 01:40 UTC on March 23. Teams that avoided the March 19 binary and Action windows could still have been exposed if they pulled those images during the later period.
Who may have been exposed?
Investigate if your organization:
- Used
aquasecurity/trivy-actionwith a mutable tag before version0.35.0. - Used
aquasecurity/setup-trivywithout a full commit-SHA pin. - Downloaded or executed Trivy
v0.69.4. - Pulled Docker Hub images tagged
v0.69.5orv0.69.6during the March 22–23 window. - Requested
version: latestintrivy-actionduring the binary compromise window. - Used a SHA-pinned wrapper that invoked a compromised setup dependency.
- Used cached, mirrored, or internally copied artifacts pulled during an affected period.
The advisory lists Trivy v0.69.3 and earlier, immutable image digests, source-built binaries, the official Homebrew formula, [email protected], safe post-incident Action commits, and known-safe full-SHA-pinned setup-trivy references as not affected under their stated conditions. These are conditional exclusions, not a blanket guarantee for every workflow or runner.
Rank #2
- Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
- FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
- Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
- Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
- Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.
A current safe tag also does not prove that an earlier workflow run was safe. Tags can move, and historical exposure depends on what the reference resolved to at execution time.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesHow to investigate
1. Stop affected execution
Temporarily disable or remove references such as:
uses: aquasecurity/trivy-action@...
uses: aquasecurity/setup-trivy@...
Do not respond by switching from one mutable tag to another. Pause cached and mirrored copies until their provenance has been checked.
2. Search workflow history, not just source files
Search workflow definitions and completed runs for:
aquasecurity/trivy-actionandaquasecurity/setup-trivy;- Trivy
v0.69.4; - Docker images labeled
v0.69.5andv0.69.6; version: latestand unpinned Action references;- composite Actions or reusable workflows that wrap Trivy.
Review runs in the March 19–20 and March 22–23, 2026 UTC windows. The advisory also recommends searching workflow logs and repositories for tpcp-docs, an indicator associated with the incident.
3. Hunt for indicators
Check DNS, proxy, firewall, and endpoint telemetry for scan.aquasecurtiy[.]org, unusual outbound HTTP POST requests from runners, unexpected cloud API activity after Trivy jobs, newly created deploy keys, OAuth grants, GitHub Apps, runners, webhooks, packages, images, or release changes.
Recommended Free Tools
On developer machines, investigate unexpected persistence involving ~/.config/systemd/user/sysmon.py and associated user systemd units. Do not assume every listed indicator appeared in every compromise.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Respond as though runner-accessible secrets may be exposed
For affected jobs, revoke old credentials before or while issuing replacements. A practical order is:
- GitHub personal access tokens, deploy keys, and GitHub App credentials.
- AWS, Azure, and Google Cloud credentials.
- Container-registry credentials.
- Kubernetes tokens and kubeconfig credentials.
- SSH keys.
- npm, PyPI, RubyGems, Maven, Docker Hub, and other package-publishing tokens.
- Signing keys, release credentials, webhooks, Slack or Teams tokens, and third-party API keys.
Changing a secret without invalidating its predecessor is not enough. The first Trivy incident demonstrated how incomplete credential rotation can preserve attacker access.
For high-value environments, rebuild affected runners, invalidate caches, inspect artifacts produced by affected jobs, and review downstream systems that accepted packages, images, deployments, or credentials from them. Persistent self-hosted runners deserve host-level forensic review and may require a complete rebuild.
Free tools Windows power users keep installed
One-click scans. No signup required.
Verify a replacement installation
Use a currently supported Trivy release after checking the project’s latest release and advisory information. Verify its signature or immutable digest. The official advisory provides this Sigstore verification example for a known artifact:
curl -sLO "https://github.com/aquasecurity/trivy/releases/download/v0.69.2/trivy_0.69.2_Linux-64bit.tar.gz"
curl -sLO "https://github.com/aquasecurity/trivy/releases/download/v0.69.2/trivy_0.69.2_Linux-64bit.tar.gz.sigstore.json"
cosign verify-blob
--certificate-identity-regexp 'https://github.com/aquasecurity/'
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com'
--bundle trivy_0.69.2_Linux-64bit.tar.gz.sigstore.json
trivy_0.69.2_Linux-64bit.tar.gz
The expected result is Verified OK. This demonstrates verification; it is not a recommendation to use v0.69.2 indefinitely.
Harden GitHub Actions
Pin every dependency to a full commit SHA
Prefer a full 40-character commit SHA:
- uses: aquasecurity/trivy-action@<full-40-character-commit-sha>
over mutable references such as:
- uses: aquasecurity/trivy-action@master
- uses: aquasecurity/[email protected]
- uses: aquasecurity/trivy-action@latest
SHA pinning prevents a tag from being retargeted, but it is not magic. Inspect composite Actions and reusable workflows recursively, and pin their dependencies too. A pinned wrapper can still invoke a mutable or compromised setup Action, download an unsafe binary, or execute code on an already-compromised runner.
Rank #4
- Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
- NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
- FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
- Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
- Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
Reduce permissions and separate trust boundaries
permissions:
contents: read
Add only the permissions a job needs. Separate scanning from package publishing, signing, and production deployment so one compromised tool does not inherit every credential. Use different jobs, identities, environments, and approval gates.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchTreat pull-request workflows as hostile, especially those using pull_request_target, attacker-controlled checkouts, runtime-downloaded scripts, or write-capable tokens. Prefer ephemeral runners, restrict runner egress, review Action changes, enforce an organization-wide allowlist, and use linters such as zizmor. GitHub’s guidance is available in its secure use of third-party Actions documentation.
Should you keep using Trivy?
There is no universal yes-or-no answer. The evidence points to a compromise of release and GitHub Actions infrastructure, not proof that Trivy’s vulnerability-detection engine is inherently unsafe. Trivy remains usable for organizations that can verify artifacts, pin dependencies, isolate runners, restrict credentials, and investigate historical executions.
A pause or reassessment is reasonable for teams that cannot audit workflow history, rotate credentials quickly, control transitive Actions, or provide stronger provenance and support guarantees required by regulated environments. A commercial scanner may offer centralized policy, support, and reporting, but changing scanners does not eliminate mutable references, overprivileged runners, weak credential rotation, or unverified dependencies.
The most directly relevant commercial category is CI/CD and GitHub Actions supply-chain hardening. Evaluate products and services for full-SHA enforcement, recursive dependency visibility, secret exposure detection, ephemeral runners, egress controls, artifact provenance, audit retention, and integration with IAM, SIEM, registries, and deployment systems. Also ask how the product itself is distributed.
The broader lesson
Security tooling is privileged software. A scanner can become an attack path when it runs in a CI job with broad credentials and unrestricted network access. The durable fix is not simply replacing Trivy: it is reducing trust, privilege, persistence, and unverified software in the entire build system.
For authoritative details, consult the official Trivy advisory, Microsoft’s analysis, and Aqua’s incident update.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

