f/technology

How a Typosquatted Domain and a Fake Version Tag Turned Trivy Into a Credential Stealer

On March 19, 2026, someone (or some group) poisoned the Aqua Security Trivy ecosystem. A tool that thousands of organizations rely on to find vulnerabilities in their container images and configurations was quietly turned into a weapon that stole their secrets instead. I spent some time pulling apart the malicious code and cross-referencing findings from Wiz’s analysis, and figured the walkthrough was worth sharing. Here’s how it happened (and how a majority of the tech industry ignored the compromise because it was a Friday).

rosesecurity.dev View

Comments

No comments yet. Log in to start the conversation.

f/technology

Technology related posts and articles

Created Feb 21, 2026

2
Members

Moderators
u/rob