kubernetes-specialist
Audited by Socket on Aug 26, 2026
2 alerts found:
Anomalyx2No clear malicious code is present in the provided manifests, but the snippet includes high-risk supply-chain execution patterns: it runs a remote bootstrap script via `curl -Ls https://get.submariner.io | bash` and downloads `clusterctl` without showing integrity verification. These are common vectors for supply-chain compromise even if the intent is legitimate multi-cluster setup. Overall, treat this as a security warning for unverified remote code execution rather than confirmed malware.
No definitive malware is evident from this YAML fragment alone (no explicit malicious endpoints, reverse shells, or hardcoded credential theft). However, supply-chain and abuse potential are materially elevated: mutable image tags in operational workloads, hostPath mounting of /proc and /sys (unusual for these tasks), and injection of AWS credentials into an opaque backup image/script that can perform high-impact data egress. Treat the referenced images as critical dependencies: pin to immutable digests, review image provenance, and restrict hostPath/scope and permissions via hardened pod/container securityContext.