@campuscodi the timing might be a coincidence but I wonder whether they use Trivy: https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23
Trivy ecosystem supply chain briefly compromised

## Summary On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credent...

GitHub
@acdha @campuscodi I'm more inclined to think it's Citrix or Ivanti. You know, don't change a winning team.