# Widely used Trivy security scanner compromised in ongoing supply chain attack

_Published Sunday, March 22, 2026 at 10:09 AM EDT · Security · Latest · Tier 2 — Notable_

![A stylized skull and crossbones made out of ones and zeroes. — Primary](https://cdn.arstechnica.net/wp-content/uploads/2020/10/malware-1000x648.jpg)

Trivy, a widely used open-source security scanner for containers and infrastructure-as-code, was compromised in an ongoing supply chain attack, Ars Technica reported.

Trivy is used by thousands of organizations to scan Docker containers and Kubernetes clusters. A compromise of the scanner is particularly dangerous because security tools run with elevated privileges.

The incident adds to a growing list of supply chain attacks targeting developer and security tooling.

## Sources

- [Ars Technica](https://arstechnica.com/security/2026/03/widely-used-trivy-scanner-compromised-in-ongoing-supply-chain-attack/)

---
Canonical: https://techandbusiness.org/newswire/Xx2NJhLQJqQVPtk0mDT6lC
Published: 2026-03-22T14:09:56.000Z
Story chronology: 2026-03-22T14:09:56.000Z
Retrieved: 2026-09-22T09:22:31.716Z
Publisher: Tech & Business (techandbusiness.org)
