Yesterday, attackers compromised Aqua Security's Trivy scanner — 75 out of 76 GitHub Action tags were force-pushed to include credential-harvesting malware. No new commits, no releases, no PRs. Just silently redirected tags.
Meanwhile, hundreds of MCP servers are being systematically forked and republished under fake registries. The supply chain attack surface for AI tooling is wide open.
https://mistaike.ai/blog/your-security-scanner-just-got-hacked

Your Security Scanner Just Got Hacked. The Supply Chain Problem Nobody Wants to Talk About.
Trivy — the vulnerability scanner running in millions of CI pipelines — was compromised yesterday. 75 out of 76 version tags were force-pushed to include credential-stealing malware. Meanwhile, hundreds of MCP servers are being systematically forked and republished under fake registries. The supply chain attack surface is growing faster than the defenses.
