TY - GEN
T1 - Infrastructure as Compromise
T2 - 16th ACM Conference on Data and Application Security and Privacy, CODASPY 2026
AU - Yang, Ruining
AU - Chaiwut, Narong
AU - Nikiforakis, Nick
N1 - Publisher Copyright:
© 2026 Owner/Author.
PY - 2026/6/22
Y1 - 2026/6/22
N2 - Infrastructure as Code (IaC) has transformed the way developers deploy and manage their infrastructure, enabling automated, reproducible, and version-controlled builds. At the same time, developer errors in IaC configurations can result in thousands of identically-vulnerable servers. In this paper, we study the so-far ignored problem of residual trust in IaC tools. IaC configurations (also known as playbooks) can refer to remote code and data that will be fetched upon execution and be incorporated in the resulting infrastructure. As such, attackers can perform supply-chain attacks against IaC environments by taking over the third-party resources that are used by playbooks during the build process. To understand the attack surface of this threat, we focus on Ansible and Puppet and quantify all the ways that developers can introduce remote references in their code. We then perform a large-scale study of publicly-Available IaC playbooks on GitHub to characterize the ways through which developers actually introduce remote references in their IaC scripts. By analyzing IaC playbooks in 247,131 repos, we identify 463 expired domains that can be immediately registered by attackers and 10,400 instances of misconfigurations in the addressed remote hosts. Our analysis also identified evidence of typosquatting errors across 30 Ansible repositories and 16 Puppet repositories, as well as a novel attack vector involving placeholder domain names. In recognition of the magnitude of the identified problems, we propose DependoScope, an extension for a popular code editor that steers developers away from erroneous remote references.
AB - Infrastructure as Code (IaC) has transformed the way developers deploy and manage their infrastructure, enabling automated, reproducible, and version-controlled builds. At the same time, developer errors in IaC configurations can result in thousands of identically-vulnerable servers. In this paper, we study the so-far ignored problem of residual trust in IaC tools. IaC configurations (also known as playbooks) can refer to remote code and data that will be fetched upon execution and be incorporated in the resulting infrastructure. As such, attackers can perform supply-chain attacks against IaC environments by taking over the third-party resources that are used by playbooks during the build process. To understand the attack surface of this threat, we focus on Ansible and Puppet and quantify all the ways that developers can introduce remote references in their code. We then perform a large-scale study of publicly-Available IaC playbooks on GitHub to characterize the ways through which developers actually introduce remote references in their IaC scripts. By analyzing IaC playbooks in 247,131 repos, we identify 463 expired domains that can be immediately registered by attackers and 10,400 instances of misconfigurations in the addressed remote hosts. Our analysis also identified evidence of typosquatting errors across 30 Ansible repositories and 16 Puppet repositories, as well as a novel attack vector involving placeholder domain names. In recognition of the magnitude of the identified problems, we propose DependoScope, an extension for a popular code editor that steers developers away from erroneous remote references.
KW - infrastructure
KW - supply-chain attacks
KW - web applications
UR - https://www.scopus.com/pages/publications/105044081046
U2 - 10.1145/3800506.3803500
DO - 10.1145/3800506.3803500
M3 - Conference contribution
AN - SCOPUS:105044081046
T3 - CODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy
SP - 126
EP - 137
BT - CODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy
PB - Association for Computing Machinery, Inc
Y2 - 23 June 2026 through 25 June 2026
ER -