
Root on Every GPU Container Start: Catching NVIDIA Container Toolkit Compromise
The NVIDIA Container Toolkit is mandatory, privileged, and almost entirely unmonitored — and most detection content written for it watches binaries that no longer execute. One docker run --gpus all produced six root executions of nvidia-cdi-hook on our test host, before the workload's first instruction. Here is what actually runs on a modern GPU node, and how Stealthium separates legitimate hook execution from abuse.











