Open-source atomic malware analysis

Analyze another

step-security/harden-runner rc

UNKNOWN
Verdict: BENIGN
“Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and…”

Referenced by 1 sample

Well-known

notable severity, 96% confident.
tool/development AutoRest code-generator header comment

Micro-behaviors

notable severity, 94% confident.
communications/http/client Opens a synchronous XMLHttpRequest GET request
notable severity, 96% confident.
communications/http/services GitHub GraphQL API endpoint
notable severity, 100% confident.
communications/socket JavaScript outbound socket connection
notable severity, 98% confident.
data/embedded PHP code fragment embedded in JavaScript
notable severity, 98% confident.
os/package-manager Runs an APT package install command
notable severity, 95% confident.
os/security systemd service ambient capabilities

Metadata

notable severity, 96% confident.
package/quality Node proxy-agent CONNECT TLS upgrade client
notable severity, 95% confident.
package/testing Jest test framework

20 of 86 traits shown

Identity

SHA-256 539ff2ee6105f31c2345dd91941bd96a92545e10a8732e084ba07dd8f03dfe8b
Canonical SHA-256 0807efb150a560ab5828f5ec9a0baffedc83b55cdb360eb635dede7886a17150
Filename rc
Package step-security/harden-runner
Version rc
PURL pkg:github/step-security/harden-runner@rc

Origin

Source upload
Ecosystem github
Domain github.com
URL https://codeload.github.com/step-security/harden-runner/tar.gz/rc

Timeline

First seen 19 Aug 2026 11:49 UTC
First analyzed 19 Aug 2026 11:56 UTC
Last analyzed 20 Aug 2026 01:28 UTC
Last updated 20 Aug 2026 01:27 UTC

Labeling

Label unknown
Label source upload