Cybersecuritynews
Supply Chain Attack Targets Aqua Trivy Extensions with Malicious AI Prompts
First seen 3 Mar 2026, 08:10 UTC
•
•26.3
Export
Article Content
Browse articles
On March 2, 2026, a supply chain attack was identified affecting developers using the Aqua Trivy VS Code extension. Unauthorized code was discovered in versions 1.8.12 and 1.8.13, which were uploaded to the OpenVSX registry on February 27 and 28, 2026. The attack involved the introduction of hidden natural-language prompts designed to hijack local coding tools.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-27
Version 1.8.12 of Aqua Trivy uploaded to OpenVSX
2026-02-28
Version 1.8.13 of Aqua Trivy uploaded to OpenVSX
2026-03-02
Supply chain attack identified affecting Aqua Trivy
2026-03-03
Articles published reporting on the attack
More articles in this cluster
Continue Reading
LiteLLM Supply Chain Attack Exposes Critical Credentials
Bitwarden CLI Compromised in Supply Chain Attack via npm
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Critical Vulnerability in Claude Code GitHub Actions Exposes Repositories to Attacks
GlassWorm Malware Campaign Targets OpenVSX with 73 Malicious Extensions
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP