huawei-cloud-mrs-host-fault-diagnose
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
AnomalyAnomalyscripts/lakewatch_api_client.py
LOWAnomalyLOW
scripts/lakewatch_api_client.py
No clear evidence of intentional malware (no reverse shell/persistence/exfiltration code or obfuscation) is present in this fragment. However, it executes a configurable external CryptoAPI binary on non-Windows platforms and provides it sensitive plaintext/ciphertext via stdin, which is a notable supply-chain risk. Additionally, TLS verification can be disabled via configuration, and the download output path is CLI-controlled without strict directory/path constraints. These warrant careful review of the CryptoAPI binary provenance and secure TLS configuration.
Confidence: 62%Severity: 55%
Audit Metadata