headscale-backup
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalyscripts/hs-migrate.sh
LOWAnomalyLOW
scripts/hs-migrate.sh
No clear evidence of intentional supply-chain malware (no exfiltration, backdoor behaviors, or suspicious network destinations) is present in the fragment. However, it performs high-impact, privileged remote restoration and constructs remote command strings using interpolated variables, creating a meaningful command-injection and trust-boundary risk if any inputs (TARGET_HOST/paths/RESTORE_SCRIPT) or the backup archive contents are not strictly validated and integrity-checked elsewhere. Overall: likely legitimate migration logic, but security-sensitive and should be reviewed for input validation, quoting/escaping, and backup authenticity verification.
Confidence: 63%Severity: 62%
Audit Metadata