Skip to content

security: PARTIAL auto-remediation — manual review required - #1499

Open
Ndevu12 wants to merge 1 commit into
mainfrom
security/auto-clean
Open

security: PARTIAL auto-remediation — manual review required#1499
Ndevu12 wants to merge 1 commit into
mainfrom
security/auto-clean

Conversation

@Ndevu12

@Ndevu12 Ndevu12 commented Aug 22, 2026

Copy link
Copy Markdown
Owner

⚠ PARTIAL remediation for Ndevu12/stayAwakeBot by StayAwakeBot Security Sentinel — this branch applies what is provably safe but is NOT a clean tree (see below).

Changes applied

  • quarantinetests/bots/security/fixtures/infected/.vscode/tasks.json
  • quarantinetests/bots/security/fixtures/infected/public/fonts
  • strip-settingstests/bots/security/fixtures/infected/.vscode/settings.json
  • strip-gitignoretests/bots/security/fixtures/infected/.gitignore

🚨 Still infected — confirmed indicators NOT auto-fixed (manual action required)

19 confirmed finding(s) could not be safely auto-remediated and remain in this tree. Do NOT merge this as a completed fix — the security gate stays red. Resolve each, then re-run saw fix --pr:

  • src/stayawake/bots/security/data/signatures.yml:263exfil-shai-hulud-branding (residual): Confirmed indicator still present after remediation — review and remove/recover manually.
  • src/stayawake/bots/security/taint/destructive.pydestructive-home-wipe (residual): Confirmed indicator still present after remediation — review and remove/recover manually.
  • tests/bots/security/fixtures/infected/.claude/settings.jsonclaude-hook-runs-payload (residual): Confirmed indicator still present after remediation — review and remove/recover manually.
  • tests/bots/security/fixtures/infected/package.jsonnpm-lifecycle-dropper (residual): Confirmed indicator still present after remediation — review and remove/recover manually.
  • tests/bots/security/fixtures/infected/postcss.config.mjs:2loader-fromcharcode-127 (born-infected): No clean version in git history and the content is packed/obfuscated — likely born infected. Review and, if confirmed, remove/quarantine it.
  • tests/bots/security/test_autorun_monitor.pydestructive-home-wipe (residual): Confirmed indicator still present after remediation — review and remove/recover manually.
  • tests/bots/security/test_destructive_intent.pysecure-home-wipe (residual): Confirmed indicator still present after remediation — review and remove/recover manually.
  • tests/bots/security/test_evasions.py:45loader-fromcharcode-127 (born-infected): No clean version in git history and the content is packed/obfuscated — likely born infected. Review and, if confirmed, remove/quarantine it.
  • tests/bots/security/test_exfil_signatures.py:33exfil-shai-hulud-branding (residual): Confirmed indicator still present after remediation — review and remove/recover manually.
  • tests/bots/security/test_installed_package_audit.py:300loader-fromcharcode-127 (born-infected): No clean version in git history and the content is packed/obfuscated — likely born infected. Review and, if confirmed, remove/quarantine it.
  • tests/bots/security/test_loader_tier_split.py:73loader-fromcharcode-127 (born-infected): No clean version in git history and the content is packed/obfuscated — likely born infected. Review and, if confirmed, remove/quarantine it.
  • tests/bots/security/test_obfuscation_file.py:663loader-fromcharcode-127 (born-infected): No clean version in git history and the content is packed/obfuscated — likely born infected. Review and, if confirmed, remove/quarantine it.
  • tests/bots/security/test_recovery.py:36loader-fromcharcode-127 (born-infected): No clean version in git history and the content is packed/obfuscated — likely born infected. Review and, if confirmed, remove/quarantine it.
  • tests/bots/security/test_scan_failclosed.py:86loader-seed-var (intrinsic-match): No clean version in history, but it is a plain literal — likely intentional (test/research data). If so, allowlist ʼloader-seed-varʼ for ʼtests/bots/security/test_scan_failclosed.pyʼ.
  • tests/bots/security/test_scan_parallel.py:31loader-seed-var (intrinsic-match): No clean version in history, but it is a plain literal — likely intentional (test/research data). If so, allowlist ʼloader-seed-varʼ for ʼtests/bots/security/test_scan_parallel.pyʼ.
  • tests/bots/security/test_tail_residuals.py:42loader-fromcharcode-127 (born-infected): No clean version in git history and the content is packed/obfuscated — likely born infected. Review and, if confirmed, remove/quarantine it.
  • tests/bots/security/test_verdict.py:117loader-seed-var (intrinsic-match): No clean version in history, but it is a plain literal — likely intentional (test/research data). If so, allowlist ʼloader-seed-varʼ for ʼtests/bots/security/test_verdict.pyʼ.
  • tests/bots/security/test_walk_delete_scope.pydestructive-home-wipe (residual): Confirmed indicator still present after remediation — review and remove/recover manually.
  • tests/bots/security/test_within_target_parallel.py:21loader-seed-var (intrinsic-match): No clean version in history, but it is a plain literal — likely intentional (test/research data). If so, allowlist ʼloader-seed-varʼ for ʼtests/bots/security/test_within_target_parallel.pyʼ.

⚠ Still needs review (not auto-fixed)

These are suspicious (heuristic) matches — possibly a legitimate inlined asset/minified file, possibly a payload the confirmed signatures didn't name. Review each; allowlist if legitimate, or remove if not.

  • exfil-shai-hulud-tokenconfig/security.yml:81
  • exfil-shai-hulud-tokendocs/explanation/credential-hygiene.md:21
  • loader-clientcode-errorsrc/stayawake/bots/security/data/signatures.yml:67
  • exfil-shai-hulud-tokensrc/stayawake/bots/security/data/signatures.yml:258
  • exfil-shai-hulud-tokensrc/stayawake/bots/security/hygiene/autorun/grade.py:527
  • exfil-shai-hulud-tokensrc/stayawake/bots/security/hygiene/models.py:42
  • exfil-shai-hulud-tokensrc/stayawake/bots/security/hygiene/runner.py:11
  • exfil-shai-hulud-tokensrc/stayawake/bots/security/taint/destructive.py:228
  • claude-hook-autoruntests/bots/security/fixtures/infected/.claude/settings.json
  • npm-lifecycle-exectests/bots/security/fixtures/infected/package.json
  • npm-lifecycle-exectests/bots/security/fixtures/infected/package.json
  • loader-decoder-fntests/bots/security/fixtures/infected/postcss.config.mjs:2
  • whitespace-concealmenttests/bots/security/fixtures/infected/postcss.config.mjs:2
  • exfil-shai-hulud-tokentests/bots/security/test_autorun_monitor.py:138
  • loader-decoder-fntests/bots/security/test_evasions.py:30
  • exfil-shai-hulud-tokentests/bots/security/test_exfil_signatures.py:2
  • loader-decoder-fntests/bots/security/test_installed_package_audit.py:300
  • loader-decoder-fntests/bots/security/test_loader_tier_split.py:79
  • loader-clientcode-errortests/bots/security/test_loader_tier_split.py:97
  • loader-decoder-fntests/bots/security/test_obfuscation_file.py:111
  • exfil-shai-hulud-tokentests/bots/security/test_pr.py:140
  • loader-decoder-fntests/bots/security/test_recovery.py:36
  • loader-decoder-fntests/bots/security/test_remediation.py:98
  • loader-decoder-fntests/bots/security/test_tail_residuals.py:46
  • loader-decoder-fntests/bots/security/test_verdict.py:117
  • exfil-shai-hulud-tokentests/bots/security/test_verdict.py:124
  • oversized-config-linetests/bots/security/fixtures/infected/postcss.config.mjs:2
  • obfuscated-source-filetests/bots/security/fixtures/infected/postcss.config.mjs

Originals are recoverable from git history. Evil-merge findings (if any) are reported separately and need a manual history rewrite.

Review and merge if correct. This is a single rolling PR — re-runs update it rather than opening duplicates.

- quarantine: tests/bots/security/fixtures/infected/.vscode/tasks.json
- quarantine: tests/bots/security/fixtures/infected/public/fonts
- strip-settings: tests/bots/security/fixtures/infected/.vscode/settings.json
- strip-gitignore: tests/bots/security/fixtures/infected/.gitignore
@Ndevu12 Ndevu12 self-assigned this Aug 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant