On March 31, 2026, a far-reaching supply chain attack on GitHub repositories was discovered. Over 300 repos were cloned as part of the incident, including code associated with AI products as well as configurations that enable access to production customer environments. The attack vector: a compromised instance of the open-source vulnerability scanner Trivy.
What Happened
Trivy, developed by Aqua Security, is one of the most widely used open-source tools for container and infrastructure scanning. It is used by thousands of companies in CI/CD pipelines to detect vulnerabilities in Docker images, Kubernetes manifests, and IaC templates (Terraform, CloudFormation).
The attack exploited a compromised GitHub Action embedded in the Trivy scan pipeline. The manipulated Action had access to the GitHub tokens of the repositories in which it was executed. With these tokens, the attackers were able to:
- Clone repository contents (source code, configuration files, secrets)
- Access linked CI/CD secrets (API keys, cloud credentials)
- In some cases: gain access to production cloud environments
According to current knowledge, over 300 repositories at various organizations are affected. The exact list is not being published for security reasons.
Why This Is Particularly Critical
The attack hits a nerve: security tools as attack vectors. Trivy is used to make software more secure. When the security tool itself is compromised, a trust problem emerges that extends beyond the individual incident.
Additionally: many of the affected repositories contain AI-related code. At a time when AI models and pipelines are increasingly business-critical, a leak of training pipelines, model configurations, or inference endpoints poses a significant risk. Attackers could:
- Reverse-engineer or clone models
- Extract training data (privacy risk)
- Manipulate inference endpoints (model poisoning)
- Exfiltrate customer data via compromised API keys
Immediate Actions
Anyone using Trivy in GitHub Actions should immediately:
- Review all GitHub Action runs from the past 14 days: Which Actions ran with which permissions? Were tokens exposed?
- Rotate all secrets: API keys, cloud credentials, database passwords that were stored as CI/CD secrets in affected repos.
- GitHub Action Pinning: Reference Actions by SHA hash, not by branch tag (e.g., @main). This prevents a manipulated version from automatically entering the pipeline.
- Check Trivy version: Aqua Security has released a cleaned version. Update to the latest version and verify checksums.
- Review audit logs: GitHub offers audit logs for organization repos. Check whether unknown clone operations have occurred.
The Bigger Lesson
This incident joins a growing list of supply chain attacks: SolarWinds (2020), Log4j (2021), 3CX (2023), XZ Utils (2024). The pattern is always the same: attackers compromise a trusted tool in the supply chain and exploit the trust that companies place in that tool.
The consequence: Zero Trust applies not only to networks and users but also to your own build pipeline. Every external dependency, every GitHub Action, every scanner is a potential attack vector. Those who do not systematically secure this (pinning, SBOM, signatures, minimal permissions) are playing Russian roulette with their own codebase.
Sources: Tech News Day, Aqua Security Advisory, GitHub Security Blog, CISA Alert.
