InfoQ·2 min read

Open Source Security Tool Trivy Hit by Supply Chain Attack, Prompting Urgent Industry Response

Trivy vulnerability scanner compromised in supply chain attack.

The widely used open source vulnerability scanner Trivy experienced a significant supply chain attack, with maintainers confirming that a malicious version was briefly distributed to users. This incident, revealed by Aqua Security, involved attackers publishing a compromised release (v0.69.4) on March 19, 2026, which was designed to exfiltrate sensitive data. The breach underscores vulnerabilities in trusted software supply chains, as attackers manipulated automated release processes and compromised credentials to propagate the malicious tool through standard distribution channels.

Key Takeaways

  • 1.

    The malicious release v0.69.4 was published on March 19, 2026.

  • 2.

    Attackers exploited compromised credentials to publish malicious artifacts.

  • 3.

    Security discussions have intensified around trust in open source tooling.

Get your personalized feed

Trace groups the biggest stories, videos, and discussions into one feed so you can stay current without scanning ten tabs.

Try Trace free