Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得通读整篇文章,抓住主要信息。 文章讲的是Trivy这个开源漏洞扫描工具被两次入侵。第一次是在2月份,一个叫hackerbot-claw的机器人利用GitHub的工作流程窃取了个人访问令牌,进而控制了仓库,发布了恶意版本。第二次是在最近,攻击者利用被妥协的凭证,强制推送了75个版本标签到恶意提交中,导致GitHub Actions中的两个动作被感染。这些动作用于扫描Docker镜像漏洞和设置Trivy工作流。攻击者通过这些恶意标签分发了一个信息窃取程序,窃取开发者的敏感信息如SSH密钥、云服务凭证等。 此外,文章还提到 Aqua Security承认这次攻击是因为之前事件的处理不彻底,导致攻击者可能获取了刷新后的令牌。建议用户使用安全版本,并采取一些缓解措施如网络级别阻止外泄域名等。 现在我要把这些信息浓缩到100字以内。需要涵盖两次入侵、GitHub Actions受影响、恶意标签导致的信息窃取、以及Aqua Security的回应和建议。 可能的结构:Trivy两次被入侵,GitHub Actions受影响,恶意标签分发窃取程序,窃取敏感信息如SSH密钥等。Aqua承认因之前事件处理不彻底导致此次攻击,并建议用户更新到安全版本并采取网络措施阻止外泄。 这样应该能控制在100字左右。 </think> Trivy开源漏洞扫描工具两次遭入侵,GitHub Actions受影响。攻击者利用恶意标签分发信息窃取程序,窃取SSH密钥、云凭证等敏感数据。Aqua Security承认因先前事件处理不彻底导致此次攻击,并建议用户更新至安全版本并采取网络措施阻止数据外泄。 2026-3-20 17:47:0 Author: thehackernews.com(查看原文) 阅读量:8 收藏

Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware that stole sensitive CI/CD secrets.

The latest incident impacted GitHub Actions "aquasecurity/trivy-action" and "aquasecurity/setup-trivy," which are used to scan Docker container images for vulnerabilities and set up GitHub Actions workflow with a specific version of the scanner, respectively.

"We identified that an attacker force-pushed 75 out of 76 version tags in the aquasecurity/trivy-action repository, the official GitHub Action for running Trivy vulnerability scans in CI/CD pipelines," Socket security researcher Philipp Burckhardt said. "These tags were modified to serve a malicious payload, effectively turning trusted version references into a distribution mechanism for an infostealer."

The payload executes within GitHub Actions runners and aims to extract valuable developer secrets from CI/CD environments, such as SSH keys, credentials for cloud service providers, databases, Git, Docker configurations, Kubernetes tokens, and cryptocurrency wallets.

The development marks the second supply chain incident involving Trivy. Towards the end of February and early March 2026, an autonomous bot called hackerbot-claw exploited a "pull_request_target" workflow to steal a Personal Access Token (PAT), which was then weaponized to seize control of the GitHub repository, delete several release versions, and push two malicious versions of its Visual Studio Code (VS Code) extension to Open VSX.

The first sign of the compromise was flagged by security researcher Paul McCarty after a new compromised release (version 0.69.4) was published to the "aquasecurity/trivy" GitHub repository. The rogue version has since been removed. According to Wiz, version 0.69.4 starts both the legitimate Trivy service and the malicious code responsible for a series of tasks -

  • Conduct data theft by scanning the system for environmental variables and credentials, encrypting the data, and exfiltrating it via an HTTP POST request to scan.aquasecurtiy[.]org.
  • Set up persistence by using a systemd service after confirming that it's running on a developer machine. The systemd service is configured to run a Python script ("sysmon.py") that polls an external server to retrieve the payload and execute it. 

In a statement, Itay Shakury, vice president of open source at Aqua Security, said the attackers abused a compromised credential to publish malicious trivy, trivy-action, and setup-trivy releases. In the case of "aquasecurity/trivy-action," the adversary force-pushed 75 version tags to point to the malicious commits containing the Python infostealer payload without creating a new release or pushing to a branch, as is standard practice. Seven "aquasecurity/setup-trivy" tags were force-pushed in the same manner.

"So in this case, the attacker didn't need to exploit Git itself," Burckhardt told The Hacker News. "They had valid credentials with sufficient privileges to push code and rewrite tags, which is what enabled the tag poisoning we observed. What remains unclear is the exact credential used in this specific step (e.g., a maintainer PAT vs automation token), but the root cause is now understood to be credential compromise carried over from the earlier incident."

The security vendor also acknowledged that the latest attack stemmed from incomplete containment of the hackerbot-claw incident. "We rotated secrets and tokens, but the process wasn't atomic, and attackers may have been privy to refreshed tokens," Shakury said. "We are now taking a more restrictive approach and locking down all automated actions and any token in order to thoroughly eliminate the problem."

The stealer operates in three stages: harvesting environment variables from the runner process memory and the file system, encrypting the data, and exfiltrating it to the attacker-controlled server ("scan.aquasecurtiy[.]org").

Should the exfiltration attempt fail, the victim's own GitHub account is abused to stage the stolen data in a public repository named "tpcp-docs" by making use of the captured INPUT_GITHUB_PAT, an environment variable used in GitHub Actions to pass a GitHub PAT for authentication with the GitHub API.

It's currently not known who is behind the attack, although there are signs that the threat actor known as TeamPCP may be behind it. This assessment is based on the fact that the credential harvester self-identifies as "TeamPCP Cloud stealer" in the source code. Also known as DeadCatx3, PCPcat, PersyPCP, ShellForce, and CipherForce, the group is known for acting as a cloud-native cybercrime platform designed to breach modern cloud infrastructure to facilitate data theft and extortion.

"The credential targets in this payload are consistent with the group's broader cloud-native theft-and-monetization profile," Socket said. "The heavy emphasis on Solana validator key pairs and cryptocurrency wallets is less well-documented as a TeamPCP hallmark, though it aligns with the group's known financial motivations. The self-labeling could be a false flag, but the technical overlap with prior TeamPCP tooling makes genuine attribution plausible."

Users are advised to ensure that they are using the latest safe releases -

"If you suspect you were running a compromised version, treat all pipeline secrets as compromised and rotate immediately," Shakury said. Additional mitigation steps include blocking the exfiltration domain and the associated IP address (45.148.10[.]212) at the network level, and checking GitHub accounts for repositories named "tpcp-docs," which may indicate successful exfiltration via the fallback mechanism.

"Pin GitHub Actions to full SHA hashes, not version tags," Wiz researcher Rami McCarthy said. "Version tags can be moved to point at malicious commits, as demonstrated in this attack."

(This is a developing story. Please check back for more details.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html
如有侵权请联系:admin#unsafe.sh