Widely used Trivy scanner compromised in ongoing supply-chain attack

2026-03-21T08:51:50Zc208153c18bf58fe12dce9d0b667bb1ac0d7c8aae53637be49ce2dee2c2239dd
AirSnitchAsusCISADarkSwordIP-KVMLLM-deanonymizationLummaNotepad++StrykerTrivyWi‑Ficertificate-expirycryptocurrency-theftdYdXexploits-in-the-wildfirmwareiOSiPhonemalwarepassword-managersrouterssecure-bootsupply-chainunicode-obfuscationwiper

What happened

Collection of recent Ars Technica security reports highlighting an active, broad threat landscape: an ongoing supply‑chain compromise of the Trivy scanner and other repo/package backdoors (including invisible/unicode obfuscation and a Notepad++ updater compromise); powerful iPhone exploit set (DarkSword) and CISA‑tracked iOS flaws being used in the wild; targeted wiper attacks (Stryker), large-scale router infections (Asus devices), and renewed malware campaigns (Lumma Stealer, malicious dYdX packages). Additional notable issues include a new Wi‑Fi bypass (AirSnitch), problems with password‑m²

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
c208153c18bf58fe12dce9d0b667bb1ac0d7c8aae53637be49ce2dee2c2239dd
Enrichment time
2026-03-21T08:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Widely used Trivy scanner compromised in ongoing supply-chain attack · Baitaphish