Trivy Vulnerability Turns Trusted CI/CD Scanner Into Supply Chain Secret-Stealing Threat
CVE-2026-33634 turned trusted Trivy releases and GitHub Actions into credential-stealing malware inside CI/CD pipelines and developer environments.
Tag archive
Package ecosystem compromise, maintainer takeover risk, and software dependency exposure.
CVE-2026-33634 turned trusted Trivy releases and GitHub Actions into credential-stealing malware inside CI/CD pipelines and developer environments.
The Mini Shai-Hulud campaign compromised more than 170 reported npm and PyPI packages, exposing how trusted publishing and provenance can still be abused when CI/CD environments are compromised.