More than 1,600 publicly available Docker Hub container images contain malicious behavior. This includes cryptocurrency mining, embedded secrets that can be used as backdoors , and DNS hijackers. Some even have embedded website redirectors.
See also: Amazon Web Services: Fixes container escape in Log4Shell hotfix

Docker Hub is a cloudwhere Docker users and contributors create, test, store, and distribute container images. Images created through Docker Hub can be run on any computer that has Docker installed.
A container image is a lightweight, self-contained, executable software package that includes everything required to run an application: code, runtime, system tools, system libraries, and settings.
Unfortunately, abuse of the service by malicious users has led to over a thousand bad uploads that put other users at risk when they deploy these images in their own containers.
Many hackers upload images with popular project names in an attempt to deceive users and make them think they are downloading a trustworthy file.
Sysdig researchers examined the problem to better understand its scale. They reported finding images that contained malicious code or mechanisms.
See also: Microsoft has fixed a vulnerability in Azure Container Instances
Tens of thousands of images with unknown status are available on Docker Hub, except those that have been verified as trustworthy by the Library Project.

Sysdig's automated scanners found 1,652 malicious images in 250,000 unverified Linux.
Out of the 608 container images analyzed, many of them were crypto-exploiters that threatened the server's resources in order to mine cryptocurrency for illegal actors.
Images containing hidden secrets rank second, with 281 instances. The secrets embedded in these images are SSH keys, AWS credentials, GitHub, NPM tokens.
Sysdig reports that the secrets may have been left in public images intentionally or by accident, which means that an attacker could have created and uploaded them.
In 2022, Sysdig warns that 61% of all images downloaded from Docker Hub come from public repositories, a 15% increase over 2021 statistics. Thus, the risk to users is becoming increasingly greater.
See also: Microsoft Github: 500GB of data leaked from the company's private repositories
Docker Hub administrators cannot monitor all uploads every day because the public library is very large, so many malicious images remain unnoticed.
What Sysdig found was that most threat actors uploaded several malicious images each. So even if a dangerous image can be deleted and the uploader banned, it doesn't significantly change the risk level of the platform.
