Talk With an Expert

Compromising Pipelines With Evil Terraform

Compromising Pipelines With Evil Terraform (PDF, 1.50MB)Last updated: 03 Oct, 2025
Presented by:
Dakota  Riley
Dakota Riley

As supply chain security continues to evolve in 2025, much of the focus remains on malicious packages in ecosystems like PyPI, NPM, and compromised GitHub Actions workflows. But what about your Terraform modules and providers?

 

In this talk, we’ll examine how infrastructure-as-code can be maliciously misused to influence CI pipelines and gain deeper access into target environments. We’ll walk through realistic attack paths that demonstrate how Terraform could be exploited in threat scenarios, complete with technical examples and a Proof-of-Concept “Evil Terraform” provider. Finally, we’ll discuss practical mitigations and security controls you can implement to reduce risk, both specific to Terraform and more broadly across your CI/CD workflows.

SANS CloudSecNext Summit 2025