T04 · Embedded Malicious Code
- Location
workflow/1688-product-analysis.js:149- Finding
Base64-Obfuscated Dynamic Python Execution
- Content
View full analysis
shellEscape(arg, dialect)).join(' ') const argsPart = extraArgs ? ` ${extraArgs}` : '' redirectedCmd = isCmd ? `${program} -c "import base64;exec(base64.b64decode('${toBase64(utf8Bytes(script))}').decode())"${argsPart} > "${outFile}" 2> "${errFile}"` : `{ ${program} -${argsPart} << '${PY_HEREDOC_DELIMITER}'\n${script}\n${PY_HEREDOC_DELIMITER}\n} > "${outFile}" 2> "${errFile}"` ``` ### Technical Analysis On Windows command shells, the workflow converts an arbitrary Python source string to Base64, inserts it into a generated shell command, decodes it at runtime, and passes the result directly to Python's `exec()` function. Base64 is not a security control. This construction obscures the effective Python program from ordinary command inspection and creates a generic dynamic-code execution primitive. The helper accepts its script through the `args` parameter rather than selecting from a strict identifier-based allowlist. The reviewed call sites currently pass locally de ...[truncated 1830 chars]- Remediation
View remediation
