Healthcare among hardest hit in Trivy supply chain compromise

The SANDCLOCK backdoor that spread through poisoned Trivy builds hit 2,500-plus organizations, with healthcare among the top sectors.

MedRisk Staff
By
2 Min Read

Healthcare organizations were among the hardest-hit sectors in the SANDCLOCK supply chain attack that spread through poisoned builds of Aqua Security’s Trivy scanner, according to new analysis. Security vendor Resecurity estimated the most affected sectors by the SANDCLOCK backdoor, planted through a code repository compromise, were technology, banking and finance, healthcare, and retail, with credentials exposed across 2,038 repositories.

The campaign, attributed to the threat actor TeamPCP behind the Shai-Hulud worm, rippled from malicious Trivy builds into downstream packages and repositories. More than 2,500 organizations were likely affected, with SOCRadar reporting that most were victims of the Trivy compromise rather than of LiteLLM, the AI gateway project that was initially blamed. Analysis of per-organization records for 2,188 entities showed data collection activity for 95 percent of them ended before the poisoned LiteLLM packages were published on March 24, aligning with the upstream Trivy compromise. The malicious code harvested credentials, tokens, and API keys, and a .pth file executed at Python interpreter startup bypassed ignore-scripts protections.

For healthcare organizations, the blast radius is credential-based: exposed secrets can feed follow-on phishing, cloud account takeover, and ransomware. Security teams should audit CI/CD pipelines for use of affected Trivy versions, rotate any credentials that may have been exposed, and review cloud identity configurations for anomalies. The incident is a reminder that widely used open source tooling is a supply chain chokepoint, and that healthcare’s dependence on shared development infrastructure carries risk well beyond the clinical network.

Share This Article