From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise