Credential Access
High
- Category
- Privilege Escalation
- Confidence
- 60% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md - `eval`, `exec`, `Function()` — code execution - `curl` / `wget` with pipe to shell — remote code download - `chmod +x` / `sudo` — privilege escalation - Reading `~/.ssh`, `/etc/passwd`, environment secrets - Network calls to unknown hosts - Base64-encoded or obfuscated commands - Install scripts that fetch from unknown URLs
