ae-data-integration-helper
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
AnomalyAnomalyreferences/logbus2_parser_plugin.md
LOWAnomalyLOW
references/logbus2_parser_plugin.md
No explicit malware logic (e.g., credential theft, reverse shell, or suspicious network destinations) is shown in the provided excerpts. However, the Logbus2 configuration indicates runtime execution of an external jar via parser.cmd with depend_sh=true, which creates a high-impact supply-chain/RCE surface if the referenced jar or configuration can be tampered with. Additionally, the Java snippet logs response content and stack traces (data exposure risk), and the gRPC client uses insecure transport. Treat as an elevated security risk pending review of the actual server-side gRPC handling and the executed parser jar/plugin behavior.
Confidence: 45%Severity: 62%
Audit Metadata