Skip to content

aquasecurity/trivy-action is compromised #541

@ashishkurmi

Description

@ashishkurmi

It looks like all the tags starting from 0.34.2 are pointing to a malicious commit which is dumping process memory to steal credential. Please update all release tags to point them to original commit.

Please refer to our blog for more details: https://www.stepsecurity.io/blog/trivy-compromised-a-second-time---malicious-v0-69-4-release#indicators-of-compromise

For example, 0.34.2 is pointing to
ddb9da4

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions