Trivy Vulnerability Turns Trusted CI/CD Scanner Into Supply Chain Secret-Stealing Threat
CVE-2026-33634 turned trusted Trivy releases and GitHub Actions into credential-stealing malware inside CI/CD pipelines and developer environments.
Author
Supply chain security reporter
Reports on dependency compromise, build pipelines, and package ecosystem risk.
CVE-2026-33634 turned trusted Trivy releases and GitHub Actions into credential-stealing malware inside CI/CD pipelines and developer environments.
The Mini Shai-Hulud campaign compromised more than 170 reported npm and PyPI packages, exposing how trusted publishing and provenance can still be abused when CI/CD environments are compromised.