Multi-CloudHow-To & HardeningRetrospectives

How to Scan Cloud Images and Containers for Compromised Packages

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2024, written in 2026 with the benefit of hindsight.

When a compromised package like XZ Utils is discovered, you need to know quickly whether it's in your cloud images and containers. Here is how to scan across Azure and AWS.

Step 1: Scan running workloads

  • Azure: Defender for Servers and Defender for Containers vulnerability assessment (Microsoft Defender Vulnerability Management) report package versions and CVEs for VMs and container images in registries and running in AKS. Search findings by CVE.
  • AWS: Amazon Inspector scans EC2, ECR images and Lambda functions. Filter by CVE.

Step 2: Scan images at build time

Add image scanning to CI/CD (for example, Trivy, Grype, or vendor scanners) and fail builds containing critical or known-compromised packages.

Step 3: Use SBOMs

Generate SBOMs for images (Syft, Docker SBOM tooling, or built-in registry features) and store them. Searching SBOMs answers "do we have package X version Y?" without rescanning.

Step 4: Check base images

Many issues come from base images. Track which base images and versions teams use, and update centrally.

Step 5: Control what gets pulled

  • Use a private registry or package proxy with approved packages.
  • Pin versions and use digests rather than floating tags like latest.
  • Verify signatures where available.

Step 6: Respond

For a compromised package:

  1. Identify affected images and hosts.
  2. Roll back to a known-good version and rebuild.
  3. Check for indicators of exploitation (for XZ, SSH behavior on exposed hosts).
  4. Rotate credentials on affected systems if exploitation can't be ruled out.

Verify

Run a quarterly "find package X" exercise and time how long it takes to get a complete answer.

scan container imagesXZ Utils backdoor2024

More on this story