Skip to main content
See every side of every news story
Published loading...Updated

How TeamPCP turned Aqua Security's own Trivy scanner into a weapon against millions of developers

Summary by The New Stack
Open source is under attack with a new wave of supply chain attacks. It has been a bad, bad few weeks for open-source security.  It all started on March 19, 2026, when a severe supply chain attack on the Aqua Security Trivy vulnerability scanner occurred, as hackers, TeamPCP, compromised the project’s continuous integration and delivery (CI/CD) pipeline and GitHub repositories repeatedly. Once in,  the attackers trojanized Trivy binaries and act…

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The New Stack broke the news in on Friday, March 27, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)
News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal