
Compromising Pipelines with Evil Terraform Providers
Source: YouTube · SANS Cloud Security · published Oct 30, 2025 · 30:05
The speaker demonstrates how attackers can compromise CI/CD pipelines by injecting malicious Terraform providers or abusing data sources to exfiltrate credentials and state files during the plan phase, bypassing traditional security controls.
Key Takeaways:
• The speaker introduces the context of increasing supply chain attacks in NPM and GitHub Actions to highlight the need for similar scrutiny in Infrastructure as Code. 0:45
• Attackers can exploit Terraform's provider ecosystem by publishing malicious providers that execute during terraform plan to steal credentials, environment variables, and state files. 12:15
• Defense strategies include enforcing network egress controls, using policy-as-code tools like Conftest, restricting provider usage via allowlists, and implementing OIDC-based identity controls for pipelines. 18:30
Understanding these attack vectors emphasizes the critical need to treat Terraform providers as trusted code and implement strict supply chain security measures to prevent pipeline compromise.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Just briefly before I talk about evil terraform and what evil things we can do with it, I just want to reintroduce myself. So, I'm Dakota Riley. My career has been a super weird collection of jumping all over the place. I've somehow accidentally managed to work for public sector, a little bit of Fang, a little bit of startups, consulting, and today I I work as a staff security engineer, which I don't even really know what that means. Uh just depends on the day. Sometimes I'm fighting with logging pipelines or doing cloud infrastructure, writing code, begging and pleading people, any mix of that. Uh geographically, I'm from northern Kentucky, which if you know where Cincinnati is, I can run from my house to Cincinnati. I can only jog out a very determined slow mile. So, uh that's that's whe…