{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sagemaker/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SageMaker"],"_cs_severities":["high"],"_cs_tags":["cloud","aws","persistence","execution"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eSecurity teams should be aware of a persistent threat vector targeting AWS SageMaker notebook instances, where attackers modify lifecycle configurations to execute arbitrary code. SageMaker allows administrators to define 'OnCreate' and 'OnStart' scripts that run with root privileges whenever an instance is provisioned or launched. Attackers leverage the 'CreateNotebookInstanceLifecycleConfig' or 'UpdateNotebookInstanceLifecycleConfig' API actions to inject base64-encoded shell scripts.\u003c/p\u003e\n\u003cp\u003eThese scripts, once decoded, often contain high-signal indicators of malicious intent, including reverse shell commands (e.g., using '/dev/tcp', 'nc -e', or 'socat'), unauthorized access to the Instance Metadata Service (IMDS) at '169.254.169.254' to steal credentials, or 'download-and-execute' patterns to fetch secondary malware. Because these configurations run as root on the notebook instance, a successful injection provides the attacker with immediate, elevated persistence and the ability to pivot within the AWS environment using the notebook's associated IAM execution role. This activity is critical for detection engineering as it represents a direct abuse of legitimate infrastructure management APIs to establish a persistent foothold.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid AWS IAM credentials with permissions to modify SageMaker configurations (e.g., 'sagemaker:UpdateNotebookInstanceLifecycleConfig').\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious script containing shell commands for persistence or credential theft.\u003c/li\u003e\n\u003cli\u003eAttacker base64-encodes the script content to bypass simple string-based inspection.\u003c/li\u003e\n\u003cli\u003eAttacker invokes the 'UpdateNotebookInstanceLifecycleConfig' API, supplying the encoded payload within the lifecycle configuration parameters.\u003c/li\u003e\n\u003cli\u003eAWS CloudTrail logs the API call, capturing the request parameters, including the base64-encoded script.\u003c/li\u003e\n\u003cli\u003eThe target SageMaker notebook instance is started or created, triggering the 'OnStart' or 'OnCreate' script execution with root privileges.\u003c/li\u003e\n\u003cli\u003eThe script executes the embedded malicious payload, establishing a reverse shell, exfiltrating IAM credentials, or downloading additional tools.\u003c/li\u003e\n\u003cli\u003eAttacker achieves persistent access to the notebook environment and uses the execution role's credentials for broader cloud reconnaissance or impact.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to bypass notebook instance security controls, gain persistent root-level access, and exfiltrate sensitive cloud credentials. If the execution role assigned to the SageMaker notebook has broad IAM permissions, the attacker can leverage these credentials to escalate privileges, access other AWS services, or exfiltrate data stored in S3 or other connected resources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring of SageMaker configuration changes and implement automated analysis of lifecycle scripts.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided ESQL detection rule to your SIEM/data platform to identify base64-encoded payloads containing high-signal malicious indicators.\u003c/li\u003e\n\u003cli\u003eEnable AWS CloudTrail logging for all SageMaker API actions, specifically 'CreateNotebookInstanceLifecycleConfig' and 'UpdateNotebookInstanceLifecycleConfig'.\u003c/li\u003e\n\u003cli\u003eAudit current lifecycle configurations to ensure they only contain approved, business-critical automation scripts.\u003c/li\u003e\n\u003cli\u003eEnforce least-privilege IAM policies, restricting 'sagemaker:CreateNotebookInstanceLifecycleConfig' and 'sagemaker:UpdateNotebookInstanceLifecycleConfig' to a small group of authorized administrators.\u003c/li\u003e\n\u003cli\u003eReview IAM roles attached to SageMaker notebooks and minimize the scope of their permissions to prevent lateral movement following a compromise.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:41:19Z","date_published":"2026-09-18T19:41:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sagemaker-lifecycle-persistence/","summary":"Threat actors are targeting AWS SageMaker notebook lifecycle configurations to achieve persistent, root-level code execution by injecting malicious scripts that trigger automatically upon instance startup.","title":"Suspicious Script Injection in AWS SageMaker Lifecycle Configurations","url":"https://feed.craftedsignal.io/briefs/2026-09-sagemaker-lifecycle-persistence/"}],"language":"en","title":"CraftedSignal Threat Feed - SageMaker","version":"https://jsonfeed.org/version/1.1"}