Credential Exfiltration via Malicious DevOps Toolkit Initialization
This rule catches a single command line that both touches a local credential file (AWS keys, SSH keys, kube/docker configs, .env, service-account JSON) and sends data over the network in the same breath — the classic signature of credential theft rather than normal use.
How the attack works
An attacker plants a fake DevOps toolkit whose 'setup' or 'init' step an AI agent runs as if it were routine tooling installation. That step reads a sensitive file — ~/.aws/credentials, id_rsa, .kube/config, .npmrc, a service-account JSON, or output from 'kubectl get secrets' — and immediately hands it to curl, wget, xh, or a scripting one-liner that opens a socket or HTTP call, either as an upload flag, piped input, or a value interpolated into a URL. Only the resulting process execution is visible, so the detection relies on seeing a credential source and a network sink appear together in one command. The rule explicitly excludes legitimate uses of credentials for authentication, such as curl --netrc or Authorization headers, since those are normal.
Netzilo detection
Netzilo reports this behaviour when it is observed.
- Signature ID
- 7f3c1a24-9d8e-4b6f-9c2a-51e0d7a4b3c8
- Severity
- High
Why it matters
If missed, an attacker gets a working copy of cloud, SSH, container-registry, or Kubernetes credentials, which can be used to pivot into cloud accounts, private registries, or clusters far beyond the original agent session.
What you can do
- →Restrict what file paths an AI agent's shell/tool execution can read, especially credential and config directories.
- →Review any agent-invoked setup or bootstrap scripts from third-party toolkits before allowing execution, and pin them to known-good versions/hashes.
- →Alert on process commands that combine a credential file path with curl, wget, xh, nc, or a scripting network call in one line, and check whether the destination is expected.
- →Rotate credentials immediately if such a command is found, and treat the source toolkit as compromised until proven otherwise.
Known benign look-alikes
- Backup or rotation scripts that intentionally upload ~/.aws/credentials, a .env or a secrets.yaml to an internal secret store with curl -T / -F / --data-binary.
- CI or cluster-bootstrap automation that pipes 'kubectl get secret -o json' or 'gcloud auth print-access-token' into an internal API with curl.
- Developer debugging that pipes 'env' into a request-inspection service to see what the environment looks like from the outside.
- Integration tests that upload dummy credential fixtures; suppressed only when the value carries an explicit placeholder marker (filter_placeholder).
- Copy-pasted documentation or demo one-liners echoed into a shell, and 'man curl' or 'curl --help' invocations (filter_help_or_demo).