17 ms·
Lots more technical research about the actual attack and how it worked here: https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise https://
by feross 6mo ago
Lots more technical research about the actual attack and how it worked here: https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise https://socket.dev/blog/trivy-under-attack-again-github-acti...
Disclosure: I’m the founder of Socket.
- joecarpenter 6mo agoGreat analysis! The Go binary was also compromised, but there's almost no information what the compromised binary did. Did it drop a python script? Did it do direct scanning? If trivy docker image was used, what's the scope (it does not include python).