Widely used Trivy scanner compromised in ongoing supply-chain attack
· Ars Technica
A significant security breach has been reported concerning Aqua Security's Trivy vulnerability scanner, a tool widely used by developers to identify vulnerabilities and hardcoded secrets in their software development pipelines. The incident, confirmed by Trivy maintainer Itay Shakury, involved hackers compromising nearly all versions of the scanner through a supply chain attack that began early Thursday. They employed stolen credentials to execute a forced push that replaced numerous version tags with malicious dependencies, putting countless developers and organizations at risk.
The forced push is a git command that circumvents protective measures designed to prevent overwriting existing commits, making this attack particularly alarming. Trivy, which boasts over 33,200 stars on GitHub, is integral to many continuous integration and continuous deployment (CI/CD) processes. In light of this breach, Shakury has advised users to assume their pipelines may be compromised and to rotate all pipeline secrets immediately.
Security firms Socket and Wiz have reported that the malware inserted into 75 of the compromised trivy-action tags is designed to scour development environments for sensitive credentials, including GitHub tokens and cloud credentials. Once these secrets are located, the malware encrypts the data and sends it to a server controlled by the attackers. This means that any CI/CD pipeline referencing the affected tags could inadvertently execute malicious code during a Trivy scan, potentially leading to severe data breaches.