id: kubernetes-dockerconfigjson-secret info: name: kubernetes.io/dockerconfigjson Secret author: dwisiswant0 severity: info reference: - https://blog.aquasec.com/the-ticking-supply-chain-attack-bomb-of-exposed-kubernetes-secrets metadata: verified: true tags: kubernetes,k8s,file,keys,secret file: - extensions: - yaml - yml extractors: - type: regex part: body regex: - \.dockerconfigjson:\s+["']?e(w|y)[\w=]+["']? # digest: 490a0046304402205837efe22bf2818e0eff1697ee0cfa3f5e769e3c20fa63e1291c6243d921daa202207523ce58ac252a1a71bbbf192eb381aa08631c976b1860127bf5e77441876053:922c64590222798bb761d5b6d8e72950