🚨 CRITICAL: Security scanner 'Trivy' has been compromised by threat actors who influenced the GitHub build process and pushed a malicious update that installs infostealer malware dubbed "TeamPCP Cloud stealer."
They created a lookalike domain (scan.aquasecurtiy[.]org) and pulled 4 malicious Golang files from it into the build process.
What it steals:
▪️ SSH keys
▪️ Cloud credentials (AWS, GCP, Azure)
▪️ Kubernetes tokens
▪️ Crypto wallets
▪️ Environment variables
▪️ 50+ sensitive file paths scanned
They created a lookalike domain (scan.aquasecurtiy[.]org) and pulled 4 malicious Golang files from it into the build process.
What it steals:
▪️ SSH keys
▪️ Cloud credentials (AWS, GCP, Azure)
▪️ Kubernetes tokens
▪️ Crypto wallets
▪️ Environment variables
▪️ 50+ sensitive file paths scanned