Compromising Pipelines with Evil Terraform Providers

Compromising Pipelines with Evil Terraform Providers

Source: YouTube · SANS Cloud Security · published Oct 30, 2025 · 30:05

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

The speaker demonstrates how attackers can compromise CI/CD pipelines by injecting malicious Terraform providers or abusing data sources to exfiltrate credentials and state files during the plan phase, bypassing traditional security controls.

Key Takeaways:
• The speaker introduces the context of increasing supply chain attacks in NPM and GitHub Actions to highlight the need for similar scrutiny in Infrastructure as Code. 0:45
• Attackers can exploit Terraform's provider ecosystem by publishing malicious providers that execute during terraform plan to steal credentials, environment variables, and state files. 12:15
• Defense strategies include enforcing network egress controls, using policy-as-code tools like Conftest, restricting provider usage via allowlists, and implementing OIDC-based identity controls for pipelines. 18:30

Understanding these attack vectors emphasizes the critical need to treat Terraform providers as trusted code and implement strict supply chain security measures to prevent pipeline compromise.

Sources:

  • 0:02 Introduction and speaker background
  • 0:45 Context on supply chain security trends in NPM and GitHub Actions
  • 12:15 Demonstration of malicious provider exploitation during plan
  • 18:30 Defensive strategies including egress controls and policy-as-code

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Just briefly before I talk about evil terraform and what evil things we can do with it, I just want to reintroduce myself. So, I'm Dakota Riley. My career has been a super weird collection of jumping all over the place. I've somehow accidentally managed to work for public sector, a little bit of Fang, a little bit of startups, consulting, and today I I work as a staff security engineer, which I don't even really know what that means. Uh just depends on the day. Sometimes I'm fighting with logging pipelines or doing cloud infrastructure, writing code, begging and pleading people, any mix of that. Uh geographically, I'm from northern Kentucky, which if you know where Cincinnati is, I can run from my house to Cincinnati. I can only jog out a very determined slow mile. So, uh that's that's whe…