VOOZH about

URL: https://thenewstack.io/repository-attacks-continue-with-backdoored-docker-images/

⇱ Repository Attacks Continue with Backdoored Docker Images - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2018-06-29 04:00:15
Repository Attacks Continue with Backdoored Docker Images
news,
Containers / Security

Repository Attacks Continue with Backdoored Docker Images

Jun 29th, 2018 4:00am by Lucian Constantin
👁 Featued image for: Repository Attacks Continue with Backdoored Docker Images

After backdoored components were found on the NPM and PyPI repositories in recent months, researchers warn that Docker Hub, another public repository, is about to distribute malicious Docker images.

At least 17 rogue images that have been uploaded in batches over the past year were found hosted under a public Docker Hub registry called docker123321. Despite multiple reports from users and security firms since September, the registry was not removed until May this year by which time the images had been pulled over 5 million times.

According to a recent analysis by researchers from Kromtech, the first three images were put up by docker123321 in May 2017 and were called tomcat, tomcat11 and tomcat22. They contained shell scripts that attempted to install reverse shells or to add authorized SSH keys on the user’s host system.

The tomcat image contained scripts that attempted to mount /etc/ from the host filesystem to /mnt/etc/ inside the container, then added a new cronjob to /etc/crontab on the host to execute a Python-based reverse shell every two minutes.

The tomcat11 image had a similar crontab-based payload delivery mechanism, but the cronjob it created set up a Bash-based reverse shell instead. Finally, tomcat22 attempted to mount /root/.ssh/ from the host, then tried to add an attacker-controlled SSH key to /root/.ssh/authorized_keys.

The second batch of malicious images was pushed to docker123321’s registry on Docker Hub between October and December 2017 with names such as kk, mysql, data and mysql0. While the payload delivery was also dependant on cronjobs, the payload itself consisted of cryptocoin mining software, particularly for Monero cryptocurrency.

The upload of rogue images under the docker123321 registry continued with new batches in January and February. Those images exhibited similar malicious behavior: The execution of reverse shells or cryptocurrency mining.

Statistics from the mining pool used by the attackers showed that just one of their wallets received 544.74 XMR (Monero coins) — around $89,000 — that were most likely mined using other people’s cloud infrastructure.

“For ordinary users, just pulling a Docker image from the DockerHub is like pulling arbitrary binary data from somewhere, executing it, and hoping for the best without really knowing what’s in it,” the Kromtech researchers said.

Docker12331 is not the only public registry on Docker Hub that was found to host malicious images rigged with Monero miners. The more concerning problem is that, until recently, there has been little to no policing done on Docker Hub regarding this issue.

Multiple parties including security firm Fortinet have publicly reported Docker12331’s images as malicious over the past year, first time in September 2017, and yet they remained up until May. Since then, other people have discovered similarly poisoned images hosted under other registries.

“We would like to apologize for the delay in responding to this thread,” a user named Jamin Wong commented this week to an issue about malicious images opened on Docker Hub’s Feedback tracker. “We have removed the reported repositories. Our team is hard at work to improve the user experience on Docker Hub.”

“As with any public repositories, Docker Hub is there for the service of the community,” Wong said. “When dealing with open public repositories and open source code, we recommend that you follow a few best practices. We recommend that users use curated official images in Docker Hub and certified content in Docker Store whenever possible. For community images, verify the content author and inspect the content of the image before running.”

“Docker does not normally police community images unless they contain illegal content,” Wong added. “We do, however, employ dedicated teams to curate official images on Docker Hub and certified images on Docker Store.”

Feature image via Pixabay.

TRENDING STORIES
Lucian is a freelance writer for The New Stack. He has been covering cybersecurity and the hacker culture for over a decade, his work appearing in many online technology publications including PCWorld, Computerworld, Network World, The Inquirer and Softpedia.com. Lucian...
Read more from Lucian Constantin
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Docker.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.