credential_harvester_test
Fail
Audited by Socket on Feb 26, 2026
1 alert found:
MalwareMalwareTOOL.py
HIGHMalwareHIGH
TOOL.py
The code implements clear credential-harvesting and exfiltration. It reads multiple high-value secrets (API keys, GitHub token, AWS credentials, SSH private keys) and attempts to send them to a hardcoded external server. This is malicious functionality and should be treated as active credential theft. Do not execute; remove and treat repository as compromised. Rotate/ revoke any potentially exposed keys. Investigate how this file entered the codebase.
Confidence: 90%Severity: 95%
Audit Metadata