# Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host Breakout (nsenter) → Kubernetes Secret Store Dump (Sysdig TRT)

> On 2026-05-29 the Sysdig Threat Research Team observed an LLM-harness-driven (agentic) threat actor exploiting an unauthenticated marimo notebook terminal (CVE-2026-39987) and running a fully automated kill chain into the container and orchestration plane: enumerating the host Docker socket, probing a kernel privilege-escalation path, creating privileged containers to break out to the host with nsenter, reading the host shadow file and SSH keys, and replaying a stolen Kubernetes service-account token to dump the cluster's entire Secret store. Sysdig assess this as the first observed operation where an agent harness — not a human — performs container escape and Kubernetes credential replay.

- **Published:** 2026-06-06T00:00:00Z
- **Last reviewed:** 2026-06-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0694
- **ID:** TL-2026-0694
- **Severity:** CRITICAL (CVSS 9.3)
- **Category:** CLOUD
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-39987

## Description

This threat documents an agentic (AI-agent-driven) post-exploitation campaign observed by the Sysdig Threat Research Team (TRT) on 2026-05-29, materially escalating exploitation of marimo CVE-2026-39987 beyond prior human-operated intrusions (TL-2026-0619, TL-2026-0352).

INITIAL ACCESS: The actor exploits CVE-2026-39987 (CVSS 9.3, CWE-306), a pre-authentication RCE in the marimo reactive Python notebook. The /terminal/ws WebSocket endpoint fails to call validate_auth() — unlike other endpoints — and directly invokes pty.fork() to spawn an interactive PTY shell to any unauthenticated client. Commands execute with the privileges of the marimo process, frequently root inside containerized deployments. The flaw was disclosed 2026-04-16, exploited in the wild within 9h41m of advisory publication, and is fixed in marimo 0.23.0.

AGENTIC POST-EXPLOITATION: Rather than a human operator, an LLM harness drove the entire kill chain. Behavioral fingerprints establishing agentic operation include: disposable base64 canary payloads ('hello', then 'hello world') written to test the staging harness before real escapes; parseable section markers (===SHADOW===, ===SSH===, _SOCK_, _K8S_, _DOCKER_) emitted to slice output between agent turns; mechanical chunked base64 staging (base64 -d /tmp/r_.b64 > /tmp/r_.py); the agent acting on directives embedded in JSON error responses and shell escape sequences that only an automated parser would process; and adaptive fallback selection (switching to nsenter when bind-mount primitives failed).

ENUMERATION: The agent issued systematic environment probes with output markers: container detection (test -f /.dockerenv), Docker socket presence (test -S /var/run/docker.sock), capability posture (grep CapEff /proc/1/status), seccomp posture (grep -i seccomp /proc/1/status), writable core_pattern (test -w /proc/sys/kernel/core_pattern), a kernel privilege-escalation reachability probe via python3 -c 'import socket;s=socket.socket(38,5,0)' (AF_VSOCK socket creation, 'Copy Fail' path), and Kubernetes projected service-account token presence (test -f /var/run/secrets/kubernetes.io/serviceaccount/token).

CONTAINER ESCAPE: With a writable Docker socket, the agent POSTed to the Docker API over the unix socket (curl --unix-socket /var/run/docker.sock /containers/create) to launch privileged containers with Binds ['/:/host'], Privileged:true, PidMode:host, NetworkMode:host and IpcMode:host — granting full host filesystem and shared namespaces. It read /host/etc/shadow (password hashes) and the SSH private key /home/deploy/.ssh/id_ed25519, then swept for more keys (find /host -name id_rsa -o -name id_ed25519 -o -name '*.pem'). When bind-mounts were unavailable it fell back to nsenter --target 1 --mount --uts --net --pid -- sh -c 'cat /etc/shadow; cat /root/.ssh/authorized_keys', entering PID 1's namespaces directly.

ORCHESTRATION-PLANE COMPROMISE: The agent read the projected Kubernetes service-account token and replayed it against the API server. A staged Python payload (delivered base64-chunked via /tmp/r_.b64) disabled TLS verification (ssl.CERT_NONE), set Authorization: Bearer <TOKEN>, queried /api/v1/namespaces/default/secrets, and dumped all Secret objects — exfiltrating keys including DATABASE_URL, DB_PASSWORD, openai-api-key and slack-webhook, e.g. postgresql://app:<redacted>@db.internal:5432/appdb. This is the orchestration-plane escalation that distinguishes this campaign from the AWS-pivot intrusion in TL-2026-0619.

INFRASTRUCTURE: marimo exploitation originated from 103.43.71.95 (AS136209 KFNetworks, South Korea); second-stage payload delivery came from 43.167.11.88 (AS132203 Aceville Pte. Ltd./Tencent, Singapore), serving http://43.167.11.88:8084/slt. No specific named threat-actor group is attributed; staging across Korean and Singaporean infrastructure suggests Asia-Pacific operational staging. BeaconBeagle returned no known C2 beacon match for either IP at time of analysis.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.006 Command and Scripting Interpreter: Python
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1204 User Execution
- T1082 System Information Discovery
- T1613 Container and Resource Discovery
- T1526 Cloud Service Discovery
- T1069 Permission Groups Discovery
- T1611 Escape to Host
- T1068 Exploitation for Privilege Escalation
- T1610 Deploy Container
- T1134.001 Access Token Manipulation: Token Impersonation/Theft
- T1552.001 Unsecured Credentials: Credentials In Files
- T1552.007 Unsecured Credentials: Container API
- T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow
- T1528 Steal Application Access Token
- T1021.004 Remote Services: SSH
- T1213 Data from Information Repositories
- T1105 Ingress Tool Transfer
- T1132.001 Data Encoding: Standard Encoding

## Sources

- [Agentic threat actor hits the orchestration plane: AI agent-driven container escape (Sysdig, Michael Clark)](https://www.sysdig.com/blog/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape)
- [Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours (Sysdig)](https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours)
- [Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure (The Hacker News)](https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html)
- [Marimo Pre-Auth RCE via Unauthenticated WebSocket Terminal CVE-2026-39987 (Resecurity)](https://www.resecurity.com/blog/article/marimo-pre-auth-rce-via-unauthenticated-websocket-terminal-cve-2026-39987)
- [CVE-2026-39987: Marimo Python Notebook RCE Vulnerability (SentinelOne)](https://www.sentinelone.com/vulnerability-database/cve-2026-39987/)
- [CVE-2026-39987 Marimo Exploit Used with LLM Agent for Post-Exploitation (Vulert)](https://vulert.com/blog/cve-2026-39987-marimo-llm-agent-post-exploitation/)
- [CVE-2026-39987 PoC — marimo Pre-Auth RCE (keraattin)](https://github.com/keraattin/CVE-2026-39987)
- [CVE-2026-39987 exploited in hours after disclosure (Security Affairs)](https://securityaffairs.com/190623/hacking/cve-2026-39987-marimo-rce-exploited-in-hours-after-disclosure.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0694
