Aqua Security is the developer of the Trivy scanner, which was compromised in the TeamPCP campaign. The company reported that attackers retained access after incomplete credential rotation and force-pushed malicious commits to Trivy repositories. Aqua also published advisories related to CVE-2026-33634.