aws-secrets-manager
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
SecuritySecurityreferences/asm-exec
MEDIUMSecurityMEDIUM
references/asm-exec
No clear in-module indicators of covert malware (no obfuscation/persistence/reverse shell), but the code is a high-impact secret-resolution and command-execution wrapper. It retrieves SecretString values from Secrets Manager (via configurable endpoints) and then injects them into arguments/environment for an arbitrary subprocess. Because endpoints are environment-configurable and tokens may be sent to SMA_ENDPOINT, an attacker who can control environment/inputs can substantially increase risk of secret exfiltration or misuse. Treat as security-sensitive in the supply chain and restrict/validate who can set endpoints and who can influence placeholders/commands.
Confidence: 72%Severity: 73%
Audit Metadata