Trivy Vulnerability Turns Trusted CI/CD Scanner Into Supply Chain Secret-Stealing Threat
CVE-2026-33634 turned trusted Trivy releases and GitHub Actions into credential-stealing malware inside CI/CD pipelines and developer environments.
Category desk
Coverage of dependency compromise, build systems, package ecosystems, and vendor risk.
CVE-2026-33634 turned trusted Trivy releases and GitHub Actions into credential-stealing malware inside CI/CD pipelines and developer environments.
The Mini Shai-Hulud campaign compromised more than 170 reported npm and PyPI packages, exposing how trusted publishing and provenance can still be abused when CI/CD environments are compromised.