Open-source atomic malware analysis

Analyze another

anchore/sbom-action v0

UNKNOWN
Verdict: BENIGN
“GitHub Action for creating software bill of materials using Syft.”

Referenced by 6 samples

Well-known

notable severity, 98% confident.
lib/runtime PHP source tree path

Objectives

notable severity, 92% confident.
persistence/login Native host uses Microsoft vendor prefix

Micro-behaviors

notable severity, 92% confident.
communications/email Mail rule action hiding matched mail
notable severity, 95% confident.
communications/http HTTP DELETE route method field
notable severity, 95% confident.
communications/http/request Builds Token auth header from JS variable
notable severity, 96% confident.
communications/http/services GitHub GraphQL API endpoint
notable severity, 94% confident.
communications/http/url Derives an origin from a URL
notable severity, 100% confident.
communications/socket JavaScript outbound socket connection
notable severity, 92% confident.
crypto/hash Node.js HMAC call in source text
notable severity, 92% confident.
data/control-flow JavaScript empty optional-binding catch
notable severity, 100% confident.
data/db ioredis driver reference
notable severity, 94% confident.
data/decode Masks character code to one byte
notable severity, 93% confident.
data/source/property Runs a high-iteration JavaScript loop
notable severity, 100% confident.
fs/file/write Node calls imported writeFileSync
notable severity, 96% confident.
os/package-manager References npm audit command

Metadata

notable severity, 95% confident.
build Action input references workflow secret
notable severity, 99% confident.
file/profile Escaped Unicode script codepoint in source
notable severity, 95% confident.
library Preserves original JavaScript console methods
notable severity, 95% confident.
package/files JavaScript package file under the dist tree
notable severity, 96% confident.
package/quality Node proxy-agent CONNECT TLS upgrade client

20 of 68 traits shown

Identity

SHA-256 0803bb698e5acc0e56fc4125651d2310657c0fd12b55b294ab9018105ecbf3a1
Canonical SHA-256 0109ff67e3c15c451cceb61661edff67b2c2b4e0ac50a6f584345912cb2776cc
Filename v0
Package anchore/sbom-action
Version v0
PURL pkg:github/anchore/sbom-action@v0

Origin

Source upload
Ecosystem github
Domain github.com
URL https://codeload.github.com/anchore/sbom-action/tar.gz/v0

Timeline

First seen 11 Aug 2026 21:50 UTC
First analyzed 11 Aug 2026 22:02 UTC
Last analyzed 23 Aug 2026 12:18 UTC
Last updated 23 Aug 2026 12:19 UTC

Labeling

Label unknown
Label source upload
Traits version 7ee52