6 ms·
Trivy under attack again: Widespread GitHub Actions tag compromise secrets
- dang 6mo agoRecent and related: Trivy ecosystem supply chain temporarily compromised - https://news.ycombinator.com/item?id=47450142 https://news.ycombinator.com/item?id=47450142 - March 2026 (35 comments)
- Shank 6mo ago> On March 22, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.5 and v0.69.6 DockerHub images. (https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23 https://github.com/aquasecurity/trivy/security/advisories/GH...) So the first incident was on March 19th and the second incident is March 22nd —- evidently the attackers maintained persistence through maybe two separate credential rotation efforts.
- woodpanel 6mo agoAs far as I understood it, their entire repo got pwnd in February, and this now is the third successful attack by the same actor.
- progbits 6mo agoFriendly reminder that just because someone is building security software it doesn't mean they are competent and won't cause more harm than good. Every month the security team wants me to give full code or cloud access to some new scanner they want to trial. They love the fancy dashboards and lengthy reports but if I allowed just 10% of what they wanted we would be pwned on the regular...
- hootz 6mo agoMost of corporate security nowadays involves "endpoint security solutions" installed on all devices, servers and VMs, piping everything into an AI-powered dashboard so we can move fast and break everything.
- cedws 6mo agoI audited Trivy's GitHub Actions a while back and found some worrying things, the most worrying bit was in the setup-trivy Action where it was doing a clone of main of the trivy repo and executing a shell script in there. There was no ref pinning until somebody raised a PR a few months ago. So a security company gave themselves arbitrary code execution in everyone's CI workflows. Aqua were breached earlier this month, failed to contain it, got breached again last week, failed to contain it again, and now the attackers have breached their Docker Hub account. Shit happens but they're clearly not capable of handling this and should be enlisting outside help.
- NewJazz 6mo agoIt seems they did end up contracting with Sygnia
- nulltrace 6mo agoThe ref pinning part is almost worse than no pinning. You can pin the action itself to a commit SHA, sure. But half the actions out there clone other repos, curl binaries, or run install scripts internally. Basically none of that is covered by your pin. You're trusting that the action author didn't stick a `curl | bash` somewhere in their own infra. Audited our CI a few months back and found two actions doing exactly that. Pinned to SHA on our end, completely unpinned fetches happening inside.
- cedws 6mo agoIn this case I'm talking about what the Action did internally. The git clone inside was not pinned, but is now.
- hrmtst93837 6mo ago
- h1fra 6mo ago/s But I thought npm was the issue, and all of this couldn't happen anywhere else?!
- hootz 6mo agoWhat if we just rebuild everything from scratch with AI? No more supply chain attacks!
- classified 6mo agoJust use OpenClaw. Oh wait, I think Microslop already did...
- classified 6mo agoDon't underestimate the prowess of Microslop to fuck up. I'm just glad I saw all of this coming and abandoned this hellscape long ago.
- staticassertion 6mo agoNo one has ever said that supply chain attacks are limited to npm.
- yieldcrv 6mo agofatiguing
- xinayder 6mo agoWasn't this discovered already last week, on Friday, that the threat actor had replaced the legit images with malware images? And republished 75 out of 76 tags?
- Shank 6mo agoNo, the actor reappeared. This article is not fully updated. On March 22nd, the actor compromised their DockerHub account and published new Docker images.
- ashishb 6mo agoI always run such tools inside sandboxes to limit the blast radius.
- wswin 6mo agoI don't think it would help here, they were stealing credentials
- tux1968 6mo agoWhenever possible, credentials shouldn't be inside the sandbox either. Credential proxying, or transparent credential injection, for example with Sandcat: https://github.com/VirtusLab/sandcat https://github.com/VirtusLab/sandcat
- ashishb 6mo ago> I don't think it would help here, they were stealing credentials So, stealing credentials in the current directory and in all other directories are the same thing?
- PunchyHamster 6mo agoThe sandbox will need internet access (to update data) and you will need to send code to test into it; so compromise already equals leaking all your code, without even breaking the sandboxing
- ashishb 6mo ago> The sandbox will need internet access (to update data) and you will need to send code to test into it; so compromise already equals leaking all your code, without even breaking the sandboxing Compromising all code in one directory is bad. Compromising all my data in all other directories, including mounted cloud drives, is worse. I restrict most dev tools to access only the current directory.
- staticassertion 6mo agoYou only need internet access to grab the image, I don't think trivy requires internet access itself. All of my image scanning tools run in isolation.
- PunchyHamster 6mo agoYou're supposed to scan for vulnerabilities, not become one!
- Pahacker 6mo ago[flagged]
- Pahacker 6mo agoGG
- huslage 6mo agoHow the heck are credential compromises still a thing with 2FA and refresh tokens???
- febusravenga 6mo agoHow bugs are still possible now when we all write everything in Rust?
- 0xbadcafebee 6mo agoSince there is no requirement for anyone to use them... people don't use them. If people aren't forced to do the right thing, they do the lazy thing.
- itscrush 6mo agoUsually through service accounts. Those are single factor.
- _slih 6mo agosecond breach in a month from the same initial credential compromise. the first rotation didn't fully revoke access. the attacker walked right back in. no persistence needed.
- deathanatos 6mo agoMy initial thought is that if this isn't a new compromise, Trivy must not have rotated the old credentials. They claim, however, > We rotated secrets and tokens, but the process wasn't atomic and attackers may have been privy to refreshed tokens … does anyone know what exactly they're talking about, here? To my knowledge, GH does not divulge new tokens after they're issued, but it depends on the exact auth type we're talking about, and GH has an absurd number of different types of tokens/keys one can use.
- dist-epoch 6mo agoOpenClaw creator made some related claims, that as soon as he created a GitHub organization with a new name, somehow it was stolen from him, and he had to ask Github people to do it for him atomically.
- tgrowazay 6mo agoIt is a bit different. What happened to openclaw: He created a new org “openclaw” to reserve the name. Then he wanted to swap it with “moltbot” org. So he opened two browser windows, one with “moltbot” repo settings another with “openclaw” repo settings. Then he renamed “openclaw” to whatever, and quickly tried to rename “moltbot” to now available “openclaw”. But in a second when “openclaw” was available, a bot snatched the repo.
- d3nit 6mo agoWell, not my best 2 weeks at work, now I have to fill out a dozen forms and sit trough a shitload of meeting, just because they got pwned (twice, or once, but really badly :D )
- ohsecurity 6mo ago[dead]
- deleted 6mo ago[deleted]
- tkzed49 6mo ago"GitHub's own security guidance recommends pinning actions to full commit SHAs as the only truly immutable way to consume an action" Why doesn't GitHub just enforce immutable versioning for actions? If you don't want immutable releases, you don't get to publish an Action. They could decide to enforce this and mitigate this class of issue.
- sieabahlpark 6mo ago[dead]
- deathanatos 6mo ago> Why doesn't GitHub just enforce immutable versioning for actions? I always wish these arguments came with a requirement to include a response to "well, what about the other side of the coin?", otherwise, you've now forced me to ask: well? The two sides of the coin: Security wants pinned versions, like you have, so that compromises aren't pulled in. Security does not want¹ pinned versions, so that security updates are pulled in. The trick, of course, is some solution that allows the latter without the former, that doesn't just destroy dev productivity. And remember, …there is no evil bit. (… I need to name this Law. "The Paradox of Pinning"?) (¹it might not be so explicitly state, but a desire to have constant updated-ness w/ security patches amounts to an argument against pinning.)
- staticassertion 6mo agoTheir question isn't about pinned versions, it's about immutable versions. The question is why it is possible to change what commit "v5" refers to, not "why would you want to write v5". You already don't get updates pulled in with the system unless they swap the version out from under you, which is not a normal way to deploy.
- irishcoffee 6mo agoOne of the only useful things my previous employer did was disallow moving tags via hg hooks.
- 6mo ago
- g947o 6mo agoPeople have been warning about giant security holes in GitHub Actions dependency but MS did nothing.
- eviks 6mo agoThey warned you!
- 0xbadcafebee 6mo ago> This allowed the threat actor to perform authenticated operations, including force-updating tags Hey look, infrastructure underpinning the security of thousands of products, being compromised in a way a simple setting could have prevented (Do not allow overriding tags is an old GH setting). Yet another reason we need a Software Building Code. I wonder how many more of these reasons we'll find in 2026.
- woodruffw 6mo agoThis is a good wake-up call (or reminder) that many “supply chain security” products are no more secure or responsibly engineered than the stacks they’re intended to protect. This is a characteristic of security software in general, but the rise of these kinds of “run us everywhere” tools/products invite new and exciting ways for an attacker to compromise large numbers of users in a single campaign.
- iam_circuit 6mo ago[dead]
- pietz 6mo agoSo by wanting to improve the security of my application, I ended up lowering the security of my application? Nice.
- momoddo 6mo ago[flagged]
- apexalpha 6mo agoThis post is from March 20 and update on 22! Not today!!! Please don’t scare people like this!
- raffraffraff 6mo agoThis has always been my big "WTH?" whenever I see people using github actions. "You're literally taking someone else's script and ruining it against your codebase"
- michaelmoreira 6mo ago[dead]
- peytongreen_dev 6mo ago[flagged]
- vel0city 6mo agoPeople should really just move away from pip/requirements.txt and move to poetry or uv. They tend to solve this problem more elegantly and through their normal default workflows.
- ddactic 6mo ago[dead]
- OutOfHere 6mo agoWhy do people still use others untrusted Actions, especially without hashes? Just have an LLM write whatever script you need to do it yourself using the necessary tools. Granted, if the underlying CLI tool itself is compromised, then avoiding the associated Action won't help you.
- emithq 6mo ago[flagged]