Amazon EKS access management and Pod Identity add IAM-native controls for granting cluster access and workload AWS permissions, but security research found they can create lateral-movement and privilege-escalation paths. An attacker who compromises an IAM principal with CreateAccessEntry and AssociateAccessPolicy permissions can create or alter an EKS access entry and potentially obtain Kubernetes cluster-admin access. EKS access policies combine cumulatively with legacy aws-auth ConfigMap mappings and Kubernetes RBAC bindings, complicating effective-permission reviews; even AmazonEKSEditPolicy, and in some cases AmazonEKSViewPolicy, may expose escalation or sensitive-data-disclosure opportunities.
Pod Identity introduces a node-local agent that supplies temporary AWS credentials to workloads, expanding the impact of node or pod compromise. A compromised hostNetwork pod may intercept plaintext traffic to the local agent endpoint and capture credentials issued to other pods on the same worker node. Organizations should audit both EKS API and Kubernetes RBAC authorization paths, limit access-entry administration, apply namespace-scoped and least-privilege permissions, protect kubelet pod-file access, and segregate untrusted workloads. IAM Roles for Service Accounts (IRSA), which uses projected service-account OIDC tokens to obtain role-specific STS credentials, remains an alternative where preventing node-local credential interception is a priority.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Wiz described how IAM principals with EKS access-entry and access-policy management permissions could grant themselves high-privilege Kubernetes access. It also showed that a compromised hostNetwork pod can intercept plaintext local Pod Identity Agent traffic and capture other pods' temporary IAM credentials on the same node.
Wiz reported that cumulative permissions across aws-auth, EKS access entries, access policies, and Kubernetes RBAC complicate access auditing. It also identified risks including theft of Pod Identity tokens from kubelet pod files and credential exposure through permissive default service-account associations.
AWS subsequently introduced EKS access management, including access entries and access policies that associate IAM users and roles with Kubernetes cluster access and permissions through the EKS API.
AWS introduced EKS Pod Identity as a mechanism for EKS workloads to obtain IAM permissions, using a node-level agent to retrieve temporary credentials for associated service accounts.
AWS introduced IAM Roles for Service Accounts (IRSA), enabling EKS pods to exchange Kubernetes service-account OIDC tokens for temporary, pod-specific IAM credentials through STS AssumeRoleWithWebIdentity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
kubernetes.io
Open sourcewiz.io
Open sourcewiz.io
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.