AI
Legitimate Kubernetes source code archive
hostile severity cross-file finding.
PowerShell script detecting emulator or sandbox environment
suspicious severity cross-file finding.
PowerShell downloads archive then executes
suspicious severity cross-file finding.
Go portForward/tunnelForward module
suspicious severity cross-file finding.
Orchestration credential paths
suspicious severity cross-file finding.
Systemd service modification and reload
notable severity cross-file finding.
Invoke-WebRequest cmdlet (iwr/wget/curl alias)
notable severity cross-file finding.
Restart=always directive
notable severity cross-file finding.
Systemd service file path reference
notable severity cross-file finding.
unzip extracts archive to directory
notable severity cross-file finding.
WantedBy autostart-enrollment directive
notable severity cross-file finding.
checking for firewall tool availability
| 0 | PK�������������������E���k8s.io/kube[email protected]/.geneUser information fingerprinting |
Objectives
hostile severity, 95% confident.
command-and-control/channel/deaddrop
URL dead drop / indirection pattern
hostile severity, 95% confident.
command-and-control/trigger
Go package init() runs network I/O on import
suspicious severity, 90% confident.
command-and-control/backdoor/proxy
Go portForward/tunnelForward module
suspicious severity, 95% confident.
command-and-control/dropper/execution
Hidden PowerShell Get-Content IEX
suspicious severity, 92% confident.
credential-access/files
Go reads SSH private key paths
suspicious severity, 94% confident.
credential-access/vpn
Go PAN-OS OpenVPN client key
suspicious severity, 98% confident.
evasion/anti-av/platform
Embedded Defender exclusion cmdlet
suspicious severity, 94% confident.
exfiltration/stealer/credential
Go system secret path list
suspicious severity, 94% confident.
impact/dos
NetScaler dd zero source
suspicious severity, 96% confident.
supply-chain/recon-exfil
curl queries cloud metadata service
Micro-behaviors
suspicious severity, 95% confident.
fs/delete
lu4p/shred secure deletion library
20 of 141 traits shown
Identity
| SHA-256 | 70ef7bfede2ffcf941be57023cad73f537ef6f017253c80df3e273454910a799 |
|---|---|
| Canonical SHA-256 | 0028c2f78748af07c3b652fb76d15f8d0a47e2dbd902d4eea710bb55657def27 |
| Filename | k8s.io-kubernetes-v0.0.0-20260616171728-41b7f6da7dfa.zip |
| Package | k8s.io/kubernetes |
| Version | v0.0.0-20260616171728-41b7f6da7dfa |
Origin
| Source | forager |
|---|---|
| Feed | pkg.go.dev |
| Ecosystem | go |
| Domain | golang.org |
| URL | https://proxy.golang.org/k8s.io/kubernetes/@v/v0.0.0-20260616171728-41b7f6da7dfa.zip |
Timeline
| First seen | 16 Jun 2026 14:37 UTC |
|---|---|
| First analyzed | 17 Jun 2026 00:14 UTC |
| Last analyzed | 17 Jun 2026 00:14 UTC |
| Last updated | 17 Jun 2026 00:14 UTC |
Labeling
| Label | unknown |
|---|---|
| Label source | forager |
| Traits version | 27202 |
Not seeing what you expected? Let us know