harbor-tactics
Audited by Socket on Aug 12, 2026
2 alerts found:
Malwarex2MALICIOUS. The skill’s declared purpose is offensive Harbor compromise, and its actual footprint matches that: credential attacks, secret harvesting, exfiltration to attacker infrastructure, persistent robot accounts, and supply-chain backdooring with a reverse shell. Even without hidden code or an installer, this is a high-risk exploit skill incompatible with benign developer-assistance use.
This fragment is strongly indicative of malicious Harbor compromise tooling. While it begins with vulnerability enumeration, it also performs persistence (creates and elevates a new sysadmin account with hardcoded credentials), credential tampering (resets other users’ passwords), monitoring reconnaissance with explicit evasion guidance, governance/provenance bypass (labeling and disabling immutable tag rules), potential upstream credential exposure via proxy-cache/registry inspection, and manual GC intended to destroy prior image layers/evidence. Do not trust or reuse this logic in any environment.