Observed Signal · Jun 8, 2026 · Supply Chain Attack · Source: DEV Community · Impact: 3/5 · Sentiment: Negative
Trivy March Supply-Chain Credential-Theft Campaign
A fast-moving supply-chain campaign beginning in late February 2026 compromised Trivy-related CI/CD artifacts and expanded across registries and images after incomplete remediation. An automated bot stole a privileged Personal Access Token (PAT) from CI, enabling attackers to push malicious artifacts to the Trivy VS Code extension and later publish a malicious Trivy binary (v0.69.4). On March 19 attackers force-pushed malicious commits to hundreds of Trivy Action tags and injected two Python infostealers that harvested environment variables, runner memory, SSH keys, cloud tokens and other secrets, exfiltrating them to attacker-controlled infrastructure or public GitHub repositories. Aqua Security disclosed the incident on March 1 and rotated credentials, but residual access remained. By March 24 the campaign moved into PyPI and NPM (poisoned Litellm packages) and Docker images; a new exfiltration endpoint (models.litellm.cloud) and additional targets (e.g., Checkmarx KICS) were reported. The reporting underscores that incomplete cleanup can turn a single breach into a sustained credential-theft campaign.
A supply-chain credential-theft campaign that abused CI/CD, package registries and container images demonstrates systemic risks from incomplete remediation and reusable service accounts; important for software and platform security though not a direct AdTech platform policy change.
Track LiteLLM Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Late February 2026: an automated bot ('hackerbot-claw') exploited a misconfigured workflow and stole a privileged Personal Access Token (PAT) from the CI environment.
- March 1, 2026: Aqua Security publicly disclosed the incident and rotated credentials, but subsequent investigation found rotation was incomplete.
- March 19, 2026: attacker published a malicious Trivy binary (v0.69.4) and force-pushed malicious commits to 75–76 of 77 tags in aquasecurity/trivy-action and all 7 tags in aquasecurity/setup-trivy.
- The injected payloads included two Python infostealers that harvested environment variables, runner memory, SSH keys, cloud tokens and other secrets, exfiltrating data to attacker-controlled domains or public GitHub repositories.
- March 24, 2026: the campaign expanded to PyPI (poisoned Litellm packages v1.82.7 and v1.82.8), later NPM and malicious Docker Hub images; a new exfiltration endpoint was identified at models.litellm.cloud and Checkmarx KICS was targeted.
Connected Companies & Entities
3 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
23,000+ Repos Had Secrets Stolen via Compromised GitHub Action
A DevOps/security post documents a major supply-chain compromise of GitHub Actions where a popular action (tj-actions/changed-files) was hijacked in March 2025, exposing AWS keys, GitHub PATs, RSA private keys and npm tokens for over 23,000 teams. The vulnerability was tracked as CVE-2025-30066. The author analyzes this and related incidents (Ultralytics December 2024, Trivy February 2026), identifies recurring root causes (tag-pinned actions, pull_request_target misuse, overly permissive GITHUB_TOKEN scopes) and presents seven practical CI/CD hardening techniques: pin actions to commit SHAs, use OIDC, restrict GITHUB_TOKEN permissions, treat workflow files like production code, use automated workflow scanners (e.g., Zizmor), mirror critical actions/private registries, and enforce branch protection and deployment gates. The piece includes a checklist of quick wins and describes how the author applied these principles while building Nexloy.
Clinejection: AI Triage Bot Enables NPM Supply-Chain Attack
Clinejection is a chained supply‑chain exploit that turned an AI‑powered issue‑triage workflow into an attack vector, resulting in an unauthorized npm publication of a malicious package. The attack combined indirect prompt injection (via a crafted GitHub issue title), GitHub Actions cache poisoning, token exfiltration, and an npm publish that added a postinstall script to install a rogue AI agent called OpenClaw. Approximately 4,000 installs occurred during an eight‑hour window before the malicious package (cline@2.3.0) was yanked. The incident highlights gaps in workflows that give LLM agents write access and long‑lived automation tokens, and underscores defenses such as OIDC provenance, lifecycle‑script inspection, and local pre‑install SCA gates.
Axios npm Package Hijacked to Install Backdoor
A malicious supply-chain attack compromised a maintainer account for the widely used Axios npm package, adding a new dependency (plain-crypto-js) whose postinstall script downloaded and executed a remote-access trojan before self-deleting. The article frames this incident as part of a broader acceleration of automated, ecosystem-scale supply-chain attacks enabled by autonomous AI coding agents that install dependencies at machine speed. It describes a related campaign called TeamPCP that began by stealing a Trivy CI token, led to a self-propagating CanisterWorm across 66+ npm packages, and cascaded into Docker Hub, PyPI and the VS Code extension marketplace. Behavioral detection (e.g., Socket) that inspects package actions rather than CVE databases can detect novel malicious packages quickly; Socket detected the suspicious dependency in minutes, while the compromised Axios versions remained live for about three hours before removal. The piece warns that AI agents selecting and installing dependencies autonomously expands the attack surface and compresses the window for human review.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
