3 ms·
This attack seems predicated on a prior security incident (https://socket.dev/blog/unauthorized-ai-agent-execution-code-published-to-openvsx-in-aqua-trivy-vs-co
by Shank 7mo ago
This attack seems predicated on a prior security incident (https://socket.dev/blog/unauthorized-ai-agent-execution-code-published-to-openvsx-in-aqua-trivy-vs-code-extension https://socket.dev/blog/unauthorized-ai-agent-execution-code...) at Trivy where they failed to successfully remediate and contain the damage. I think at this time, Trivy should’ve undertaken a full reassessment of risks and clearly isolated credentials and reduced risk systemically. This did not happen, and the second compromise occurred.
- NewJazz 7mo agoThey did a lot of what you describe, although perhaps not well enough.
- Shank 7mo agoIt seems not enough again, as their Docker images have now been compromised (as of March 22nd, 2026): https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23 https://github.com/aquasecurity/trivy/security/advisories/GH...