Skip to main navigation Skip to search Skip to main content

Infrastructure as Compromise: Abusing Residual Trust in Infrastructure as Code Tools

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Infrastructure as Code (IaC) has transformed the way developers deploy and manage their infrastructure, enabling automated, reproducible, and version-controlled builds. At the same time, developer errors in IaC configurations can result in thousands of identically-vulnerable servers. In this paper, we study the so-far ignored problem of residual trust in IaC tools. IaC configurations (also known as playbooks) can refer to remote code and data that will be fetched upon execution and be incorporated in the resulting infrastructure. As such, attackers can perform supply-chain attacks against IaC environments by taking over the third-party resources that are used by playbooks during the build process. To understand the attack surface of this threat, we focus on Ansible and Puppet and quantify all the ways that developers can introduce remote references in their code. We then perform a large-scale study of publicly-Available IaC playbooks on GitHub to characterize the ways through which developers actually introduce remote references in their IaC scripts. By analyzing IaC playbooks in 247,131 repos, we identify 463 expired domains that can be immediately registered by attackers and 10,400 instances of misconfigurations in the addressed remote hosts. Our analysis also identified evidence of typosquatting errors across 30 Ansible repositories and 16 Puppet repositories, as well as a novel attack vector involving placeholder domain names. In recognition of the magnitude of the identified problems, we propose DependoScope, an extension for a popular code editor that steers developers away from erroneous remote references.

Original languageEnglish
Title of host publicationCODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy
PublisherAssociation for Computing Machinery, Inc
Pages126-137
Number of pages12
ISBN (Electronic)9798400725623
DOIs
StatePublished - Jun 22 2026
Event16th ACM Conference on Data and Application Security and Privacy, CODASPY 2026 - Frankfurt am Main, Germany
Duration: Jun 23 2026Jun 25 2026

Publication series

NameCODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy

Conference

Conference16th ACM Conference on Data and Application Security and Privacy, CODASPY 2026
Country/TerritoryGermany
CityFrankfurt am Main
Period06/23/2606/25/26

Keywords

  • infrastructure
  • supply-chain attacks
  • web applications

Fingerprint

Dive into the research topics of 'Infrastructure as Compromise: Abusing Residual Trust in Infrastructure as Code Tools'. Together they form a unique fingerprint.

Cite this