Title: Supply-Chain Attack Targets Aqua Security’s GitHub, Spreads Malware Through Docker
In a concerning cybersecurity incident, the TeamPCP hacking group has breached Aqua Security’s GitHub organization, compromising the popular Trivy vulnerability scanner. The attackers injected malicious code into the software, which is widely used to detect vulnerabilities across various platforms.
The breach occurred when TeamPCP exploited a service account, allowing them to publish harmful Docker images and alter repository descriptions. This incident affects users of Trivy, which has over 33,800 stars on GitHub, raising significant concerns within the development community.
While Aqua Security has released safe versions of Trivy and engaged incident response teams, the incident highlights the ongoing threat of supply-chain attacks. To protect against similar incidents, organizations should implement multi-factor authentication for service accounts and regularly monitor their repositories for unauthorized changes.
Risk Level: High
This attack underscores the vulnerability of widely-used software tools and the potential for widespread impact.
Source: View Original Report
