top of page
perceptive_background_267k.jpg

10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions

Published:

2 juli 2026 om 14:51:07

Alert date:

2 juli 2026 om 15:02:30

Source:

stepsecurity.io

Click to open the original link from this advisory

Supply Chain & Dependencies, Identity & Access, Data Breach & Exfiltration, Security Tools

TeamPCP compromised 76 Trivy version tags overnight in a supply chain attack targeting GitHub Actions workflows. A similar attack called KICS followed the same playbook shortly after. The attacks aimed at credential exfiltration by injecting malicious code into widely-used GitHub Actions. StepSecurity details how their platform's ten independent security layers work together to detect and prevent such attacks. The article covers runtime detection of compromised actions, blocking credential exfiltration, and incident response across organizations. The campaign highlights the growing threat of supply chain attacks targeting CI/CD pipelines. One security control alone is insufficient to stop sophisticated multi-stage supply chain attacks.

Technical details

Mitigation steps:

Affected products:

Trivy
GitHub Actions
KICS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page