In late February 2026 an automated bot called hackerbot-claw abused a misconfigured GitHub Actions workflow in Aqua Security's open source Trivy scanner and stole a privileged personal access token (PAT). Aqua disclosed the incident on 1 March 2026 and rotated credentials, but the rotation was incomplete. On 19 March 2026 an attacker who calls itself TeamPCP used access that survived the clean-up, including Aqua's aqua-bot service account, to publish a malicious Trivy v0.69.4 release and force-push most version tags of the trivy-action and setup-trivy GitHub Actions to an infostealer. Any pipeline that ran those tags during the exposure window handed over its CI/CD secrets, cloud keys and tokens. Wiz reported a parallel compromise of Checkmarx's KICS GitHub Action on 23 March, and the LiteLLM project believes its own compromise the next day started with Trivy in its CI pipeline. Aqua says its commercial products were not affected, and the advisory is tracked as CVE-2026-33634.
Key takeaways
- The root credential was a PAT stolen through a
pull_request_targetworkflow by hackerbot-claw, an account that StepSecurity says describes itself as an "autonomous security research agent powered by claude-opus-4-5". - Aqua rotated credentials after disclosing the first incident on 1 March 2026, but by its own account the rotation "was not fully comprehensive", leaving the attacker with still-valid credentials and the aqua-bot service account.
- On 19 March 2026 the attacker pushed malicious Trivy v0.69.4 and moved 75 of 76 trivy-action tags (Aqua counts 76 of 77) and all 7 setup-trivy tags to commits carrying a stealer that read secrets from GitHub Actions runner memory.
- This is a confirmed NHI breach with downstream victims: LiteLLM believes its PyPI compromise started with Trivy in its CI pipeline, and Wiz reported a parallel compromise of Checkmarx's KICS GitHub Action days later.
- The identity lesson: a credential rotation that misses one token, bot account or publishing key does not end an incident, it pauses it.
At a glance
| Organisations | Aqua Security (Trivy open source scanner, trivy-action, setup-trivy, Trivy VS Code extension); downstream users whose pipelines ran the poisoned releases |
|---|---|
| When | PAT stolen 27 to 28 February 2026; first disclosed 1 March 2026; main compromise 19 March 2026; Docker Hub images 22 March 2026 |
| Attacker | hackerbot-claw (first intrusion); the 19 March payload self-identifies as "TeamPCP Cloud stealer", which Socket noted could be a false flag |
| Entry point | A pull_request_target workflow ("API Diff Check") that ran fork code with repository secrets, then credentials left valid after an incomplete rotation |
| Identities abused | A privileged GitHub PAT; the aqua-bot service account; an Open VSX publishing token; then GitHub tokens, cloud keys, SSH keys and Kubernetes tokens from victims' CI runners |
| Impact | Malicious Trivy binary and container images, 80+ poisoned Action tags, internal Aqua repositories made public, and stolen CI secrets reused against other projects |
| Category | NHI, Agentic AI and AI agents. Incident class: confirmed NHI breach (stolen PAT and bot account used to publish malware that stole CI/CD credentials) |
What happened
Trivy is one of the most widely used open source vulnerability scanners, and many teams run it in CI through Aqua's trivy-action and setup-trivy GitHub Actions. Between 21 February and 2 March 2026, StepSecurity tracked a GitHub account named hackerbot-claw attacking workflows in seven public repositories. At aquasecurity/trivy, StepSecurity says a pull request triggered the "API Diff Check" workflow, which used the pull_request_target trigger and so ran with the repository's privileges. The injected code stole a PAT. According to Aqua's disclosure as cited by StepSecurity, the token was used to make the repository private and rename it, delete releases from 0.27.0 to 0.69.1, and publish a suspicious artifact to the Trivy VS Code extension on Open VSX.
Socket found that extension versions 1.8.12 and 1.8.13, published on 27 and 28 February, contained code that launched five local AI coding tools, including Claude, Codex, Gemini, Copilot CLI and Kiro, in their most permissive modes, with prompts asking them to collect credentials and tokens and report them out. Socket said there were "no confirmed reports of successful exfiltration". The publisher account belonged to a former Aqua employee; the token was revoked on 28 February. Aqua restored the repository, republished v0.69.2 and rotated credentials on 1 March.
That rotation is where the incident turned into a campaign. Itay Shakury, Aqua's VP of open source, told The Hacker News: "We rotated secrets and tokens, but the process wasn't atomic, and attackers may have been privy to refreshed tokens". At about 17:43 UTC on 19 March, according to the GitHub advisory, a malicious tag was pushed that triggered Trivy's release pipeline and published v0.69.4. Wiz says the attacker used the compromised aqua-bot service account, took its GPG keys and Docker Hub, Twitter and Slack credentials, and force-pushed trivy-action and setup-trivy tags to malicious commits that kept the original metadata. The stealer scraped the GitHub Actions Runner.Worker process memory, searched more than 50 file paths for SSH keys, cloud credentials and Kubernetes tokens, encrypted the haul and sent it to a domain typosquatting Aqua. If that failed, it used the victim's own GitHub token to create a repository named tpcp-docs and upload the data there.
Aqua says it contained the release by about 20:38 UTC on 19 March (the GitHub advisory lists exposure windows running to about 21:42 UTC for v0.69.4 and about 05:40 UTC on 20 March for trivy-action), but the attacker came back. On 22 March malicious Trivy images tagged 0.69.5 and 0.69.6 appeared on Docker Hub, and at about 21:40 UTC internal Aqua repositories were published to GitHub as public repositories. Aqua brought in Sygnia, and its 1 April update said that "the rotation was not fully comprehensive, allowing the threat actor to retain residual access via still-valid credentials." It also said: "There continues to be no indication that Aqua's commercial products have been affected."
Timeline
| Date | Event |
|---|---|
| 20 February 2026 | The hackerbot-claw GitHub account is created, according to StepSecurity. |
| 27 February 2026 | Trivy VS Code extension 1.8.12 with AI agent prompts is published to Open VSX (Socket). |
| 28 February 2026 | StepSecurity records a payload running through the API Diff Check workflow and the stolen PAT pushing a commit; the extension token is revoked. |
| 1 March 2026 | Releases are deleted and the repository renamed; Aqua discloses the incident, restores the repository and rotates credentials. |
| 19 March 2026 | Malicious v0.69.4 is released and trivy-action and setup-trivy tags are force-pushed; Aqua contains it the same evening. |
| 21 March 2026 | Aqua publishes advisory GHSA-69fq-xp46-6x23 (CVE-2026-33634). |
| 22 March 2026 | Malicious Docker Hub images 0.69.5 and 0.69.6 appear and internal Aqua repositories are made public. |
| 23 March 2026 | Wiz reports a parallel compromise of Checkmarx's kics-github-action; Aqua engages Sygnia. |
| 24 March 2026 | Poisoned LiteLLM versions 1.82.7 and 1.82.8 are reported carrying the same infostealer (GitGuardian). |
| 1 April 2026 | Aqua says the investigation is nearly complete and confirms the March 1 rotation was incomplete. |
How it happened: the identity attack path
- A workflow that trusted fork code. The API Diff Check workflow used
pull_request_target, so code from an outside pull request ran with access to a privileged PAT. - A token with far more reach than its job. The stolen PAT could delete releases, rename the repository and push commits, and a separate Open VSX token held by a former employee let the attacker publish extension updates.
- An incomplete rotation. Aqua rotated secrets on 1 March, but not atomically. Valid credentials, including access to the aqua-bot service account, survived.
- A trusted bot ships the malware. On 19 March the aqua-bot account triggered a release and mutable version tags were repointed, so every pipeline that referenced trivy-action by tag pulled the stealer.
- Victims' CI secrets harvested and reused. The stealer read secrets from runner memory and disk, and LiteLLM believes credentials taken this way led to its own compromise.
Impact
- Confirmed: malicious Trivy v0.69.4 on GitHub Releases and container registries, Docker Hub images 0.69.5 and 0.69.6, poisoned trivy-action and setup-trivy tags, and internal Aqua repositories made public, according to Aqua and Wiz.
- Downstream: LiteLLM believes its PyPI compromise originated from Trivy in its CI/CD scanning workflow. Wiz reported a parallel compromise of Checkmarx's kics-github-action on 23 March, and GitGuardian says the campaign targeted Checkmarx KICS the following day.
- Not affected: Aqua says there is no indication that its commercial products were affected.
- Potential: any organisation that ran an affected tag between 19 and 20 March should treat every secret available to that pipeline as stolen. The number of affected pipelines has not been published.
What this means for NHI and AI agent security
Every step of this attack ran on non-human identities: a PAT exposed to a workflow, a bot account that could publish releases, a publishing token owned by someone who had left, and the GitHub tokens and cloud keys held by thousands of CI runners. Security scanners run in privileged pipelines with broad read access, so one compromised scanner exposes every secret in every pipeline that runs it.
The AI angle runs both ways. The initial intrusion came from an account that presents itself as an autonomous agent, scanning and exploiting workflows at machine speed. The malicious extension then tried to turn developers' own coding agents into collectors by starting them with approvals switched off. Both point to the same control: agents and bots need narrowly scoped, short-lived credentials and no standing access to publish. See our CI/CD Pipeline Identity Security Guide and AI Coding Agents Security Guide.
The deeper lesson is about remediation. GitGuardian put it plainly: "The bigger lesson is that incomplete cleanup turns one breach into a campaign." Rotation has to cover every credential the attacker could have reached, including bot and service accounts, and has to be verified, not assumed. Our Leaked Credential Response Playbook sets out that sequence.
Recommendations
- Pin GitHub Actions to full commit SHAs. As Wiz says, "Pin GitHub Actions to full SHA hashes, not version tags." Tags can be moved; SHAs cannot. See our CI/CD Pipeline Identity Security Guide.
- Remove pull_request_target from workflows that touch secrets. Never check out or run fork code in a privileged context, and audit existing workflows for this pattern.
- Rotate atomically and verify it. After an incident, revoke every token, bot credential, signing key and publishing token the attacker could have reached at the same time, then confirm each old credential fails. See our Leaked Credential Response Playbook.
- Treat bot and service accounts as privileged identities. Give release bots the minimum scope, require protected branches and tags, and alert on unusual releases. See our Service Account Security Guide.
- Offboard publishing tokens with people. Marketplace and registry tokens held by former employees should be inventoried and revoked at exit. See our Joiner-Mover-Leaver Guide.
- Hunt for the indicators. Search for
tpcp-docsrepositories and check workflow logs from 19 and 20 March 2026.
Frequently asked questions
How was Trivy compromised in March 2026?
An attacker used credentials that survived Aqua's incomplete rotation after an earlier February intrusion, including the aqua-bot service account, to publish malicious Trivy v0.69.4 and force-push trivy-action and setup-trivy tags to an infostealer on 19 March 2026. The original credential was a PAT stolen through a pull_request_target workflow.
Which Trivy versions are affected and which are safe?
According to Aqua's advisory, Trivy v0.69.4, Docker Hub images 0.69.5 and 0.69.6, trivy-action tags below 0.35.0 and setup-trivy tags below 0.2.6 were affected during the exposure windows. Trivy 0.69.3, trivy-action 0.35.0 and setup-trivy 0.2.6 are listed as safe.
What is the link between Trivy and the LiteLLM breach?
Malicious LiteLLM versions 1.82.7 and 1.82.8, published to PyPI on 24 March 2026, carried the same stealer. LiteLLM's maintainers said: "We believe that the compromise originated from the Trivy dependency used in our CI/CD security scanning workflow." Our separate LiteLLM page covers that breach in detail.
Related NHI Mgmt Group resources
LiteLLM PyPI Package Breach 2026 · Checkmarx KICS supply chain attack 2026 · tj-actions/changed-files Compromise 2025 · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
The Trivy attack shows how one stolen pipeline token and one missed rotation can spread across an ecosystem. We help teams map the tokens, bot accounts and publishing credentials in their pipelines, scope them down and build an incident playbook that closes every path. See our NHI and AI agent security training.
References
- StepSecurity: hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions (1 March 2026)
- Socket: Unauthorized AI Agent Execution Code Published to OpenVSX in Aqua Trivy VS Code Extension (2 March 2026)
- Wiz: Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack (20 March 2026)
- The Hacker News: Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets (20 March 2026)
- Aqua Security (GitHub advisory): Trivy ecosystem supply chain temporarily compromised (21 March 2026)
- LiteLLM: Security Update: Suspected Supply Chain Incident (24 March 2026)
- GitGuardian: Trivy's March Supply Chain Attack Shows Where Secret Exposure Hurts Most (24 March 2026)
- Aqua Security: Update: Ongoing Investigation and Continued Remediation (1 April 2026)