A new attack technique recently revealed allows authenticated users of the popular GitOps tool ArgoCD to extract strong Git credentials.
See also: Kimsuky exploits GitHub to distribute malware

The method, discovered by cybersecurity research group Future Sight, exploits Kubernetes' internal DNS resolver to intercept credentials in transit, posing a significant risk to organizations that rely on the continuous delivery tool.
ArgoCD, a leading project in the Cloud Native Computing Foundation (CNCF), works by pulling Kubernetes manifests from a Git repository to maintain the desired state of applications. To achieve this, it stores credentials for connecting to Git servers like GitHub.
While these credentials are hidden in the ArgoCD interface for security reasons, this new attack finds a way to capture them during the login process.
The heart of the technique is an internal DNS spoofing. An attacker who has compromised an ArgoCD account with a specific set of permissions can deploy a malicious service within the same Kubernetes cluster. This service is named so that it intentionally clashes with the domain of a legitimate Git repository, such as github.com.
See also: GhostAction campaign steals 3325 secrets in GitHub attack

Because of the way Kubernetes handles DNS, pods, including the ArgoCD repository server, will first attempt to resolve domain names against the cluster's internal DNS. The malicious service creates a DNS record that points to github.com on its own internal IP address.
As a result, when ArgoCD tries to sync a repository, it mistakenly sends the connection request not to the real GitHub, but to the attacker's proxy service, Future Sight reported. This service, which the researchers named "Argexfil," can then capture the credentials before forwarding the traffic to the real Git server to avoid suspicion.
This method remains effective even when the repositories use secure HTTPS. The attack relies on the attacker having permissions to add custom certificates to ArgoCD. By creating a self-signed certificate for their malicious service and adding it to ArgoCD's list of trusted certificates, the attacker can successfully perform a man-in-the-middle (MitM) attack and decrypt the traffic, exposing the credentials.
According to the researchers, the ArgoCD team was made aware of the technique. While they recognized the innovative approach, they did not classify it as a direct vulnerability within ArgoCD, attributing the risk to Kubernetes' default DNS behavior and insecure user permission configurations.
See also: Banana Squad: Malicious GitHub repositories distribute malware

To defend against this technique, organizations are advised to:
– They enforce the principle of least privilege, limiting user permissions to the bare minimum.
– They strictly limit which users can add or modify certificates in ArgoCD.
– They enforce strong monitoring of both the ArgoCD application and internal Kubernetes network traffic.
– They use SSH-based Git connections where possible, as the key exchange mechanism is not vulnerable to this method of credential theft.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
