huawei-cloud-ecs-dsh-deploy
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
AnomalyAnomalyscripts/deploy_dsh.py
LOWAnomalyLOW
scripts/deploy_dsh.py
No explicit malware/backdoor behavior is present in the shown code fragment. The script is a high-impact infrastructure automation/orchestration tool that provisions ECS resources and triggers remote deployment via COC/UniAgent, running under a default root execution context. The most concrete security concern in this fragment is sensitive credential exposure (server initial password printed to console and potentially included in notifications). The primary supply-chain/sabotage risk would reside in the imported helper modules and the COC deployment scripts they invoke; those are not visible here, so confidence in malware absence is limited.
Confidence: 42%Severity: 65%
Audit Metadata