Obfuscated Code
An agent runs a snippet after a safety scan. The scan flags a dangerous call — eval, exec — whose argument is a readable command (curl … | sh). It does not understand the string, only reads it.
Get a payload to run that the scanner cannot read — the dangerous command must not appear as plain text in the call.
No leads yet. Declassify intel one step at a time when you’re stuck.
How this attack works
The scanner matched the text of the argument passed to the exec sink. Encoding the command as base64 made that text meaningless; the snippet decoded it at runtime and executed the result, so the dangerous string never appeared for the scanner to see.
Why it's dangerous
Decode-then-execute is one of the most common shapes of real npm and PyPI malware: the package looks inert, then reconstructs and runs its payload at install or import time. Any defense that only reads string literals is blind to it. SkillTotal flags a decode call feeding an exec sink as ST-OBF-DECODE-EXEC, regardless of the encoding.
OWASP mapping
Maps to OWASP Top 10 for LLM Applications (2025): LLM05: Improper Output Handling (executing model- or dependency-supplied code). SkillTotal’s ST-OBF-DECODE-EXEC flags decode-then-run across languages.
How to defend
- Flag the structure, not the string: a decode (atob/Buffer.from/fromCharCode) feeding eval/Function/exec is the signal.
- Forbid dynamic code execution entirely where you can; there is rarely a legitimate `eval(decode(...))`.
- Run untrusted code in a sandbox with no network egress and no credentials.
- Scan at the AST level, after constant-folding obvious decodes, not with text regexes alone.
SkillTotal catches this class of issue deterministically (rule ST-OBF-DECODE-EXEC).
FAQ
- Isn't eval always obvious?
- The call is; the payload is not. Scanners and reviewers often allow eval/Function and only inspect the argument. Encoding the argument defeats that, which is why the decode→exec pair, not eval alone, is the thing to flag.
- Why does real malware do this?
- To pass registry scanning and casual review. The published source looks benign; the malicious command only exists after a runtime decode, at install or import time.