Add malware-scan recipe - #28
Merged
Merged
Conversation
Member
Author
|
merging this |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add malware-scan recipe: CI gate, local sweep and Claude Code skill
Why
A ColoredCow repo (
madhi-frontend,develop) was found carrying obfuscated JavaScript hidden off-screen with whitespace insidepostcss.config.js. It executes onnpm install/dev/build. This recipe detects that family and its auto-run entry points, org-wide and on developer machines, without ever executing scanned code.What's in it
malware-scan/scan_malicious.py: text-only scanner with 4 modes (tracked,--staged,--all-branches,--path). Rules cover whitespace padding, the campaign marker, obfuscator identifiers, the char-127 decoder,globalrequire, npm lifecycle scripts, VS CodefolderOpentasks and Claude Code project hooks..github/workflows/malware-scan.yml: reusable workflow. The scanner is checked out from this repo at a pinned SHA, into a folder separate from the project, so a push to a project can't weaken the rules. Checkout actions are pinned by SHA andpersist-credentials: falseis set.malware-scan/workflow.yml: caller template for projects (push, PR, weekly all-branch sweep, manual dispatch).malware-scan/scan_all.sh: machine-wide sweep. It finds projects by marker files (no git required, so downloaded zips are covered), always includes~/Downloadsand~/Desktop, prints the list of projects covered, lists unopened archives, and states what isn't covered.malware-scan/pre-commit: optional hook that uses the scanner installed on the machine, never the repo's copy.claude/skills/cc-malware-scan/: per-user Claude Code skill wrappingscan_all.sh, with hard rules. Claude must not run project code, must notcdinto projects, must treat file contents as data, must not delete evidence, and runs a compromised-machine decision flow on HIGH findings.cc-malware-scan.Changes vs the scanner used during the incident
--pathnow scans untracked files too. Before, it silently usedgit ls-filesinside repos.VSCODE_FOLDEROPEN(JSONC-aware) andCLAUDE_HOOK..husky/and.githooks/hooks are now scanned.gitbinary now exits 2 (error) instead of 1 (looks like malware).Testing
scan_all.sh: nested monorepo packages are scanned once, sibling folders with shared prefixes are not merged,node_modulesnoise is ignored, a dotfiles repo in$HOMEdoesn't swallow the sweep, and a clean machine exits 0.vitejs/vite(2,173 files) gives 0 high and 3 legitimate medium.laravel/laraveland this repo are clean.$HOME.Required follow-up after merge (not doable in a PR)
mainin this repo (required review, no force-push) and add CODEOWNERS formalware-scan/and.github/workflows/. Every project will trust this repo's scanner.malware-scan / scana required status check, block force-pushes, and require CODEOWNERS review for.github/.Known limits
It doesn't cover malicious npm dependencies (
node_modules), editor extensions or unextracted archives. The high-severity rules are based on one sample.