A mutating admission webhook rewrites objects before they are stored. Pointed at an attacker endpoint and scoped to pods, it injects into every new workload: an extra sidecar container, a hostPath volume, or a modified command. The injection is automatic and cluster-wide, so legitimate deployments carry the attacker's code.
# Registration (requires admissionregistration write): a MutatingWebhookConfiguration
# matching pods, pointed at the attacker's webhook service, that returns a JSONPatch
# adding a privileged sidecar to spec.containers.
kubectl get mutatingwebhookconfigurations
Exploitation notes#
- Injecting a privileged or hostPath sidecar re-establishes node access on every new pod, so the foothold regenerates faster than defenders remove it.
- Scope the webhook narrowly (namespaces, labels) to limit noise while still covering high-value workloads.
- It needs write to
mutatingwebhookconfigurationsand a reachable webhook endpoint; a benign configuration name helps it blend in.