Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Supply Chain Attacks

Trivy Supply-Chain Attack Uses ICP Smart Contracts for C2 Communications

2 reports · First detected 2026-03-24 · Last active 2026-03-24

Trivy is an open-source vulnerability scanner maintained by Aqua Security and widely integrated into software delivery pipelines such as GitHub Actions. The supply-chain attack allowed hackers to infiltrate development environments through a trusted tool and steal API keys and credentials. They also concealed command-and-control communications through smart contracts on the Internet Computer, or ICP, blockchain, making the activity harder to block and trace.

A March 24 security advisory said hacking group TeamPCP had compromised Trivy's GitHub Actions workflow to distribute information-stealing malware while also launching a supply-chain attack against the npm registry. A subsequent investigation found that the CanisterWorm worm used an ICP Canister as a hub for exchanging C2 information. More than 10,000 workflows have been affected, and no precise financial losses have been disclosed.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)