Microsoft details a Trivy supply chain compromise that allowed attackers to deliver credential-stealing malware via trusted distribution channels into CI/CD pipelines. The post provides an overview of the attacker's techniques and offers guidance for security teams on detection, investigation, and defense methods.