ANSI escape sequences in files you print
Some bytes in a file are not characters a terminal prints. They are instructions it carries out, the moment you cat, less or grep the file.
ESC[8m concealOSC 52 clipboard writeOSC 8 hyperlinkterminal injection
What each one does, spelled out
$ augur scan install.sh
install.sh (text): 6 finding(s)
TERMINAL
[alarm] offset 39 — ESC[8m — conceal: hides the text that follows
4 bytes, looks like ansi escape
[alarm] offset 75 — terminal command (OSC): writes to the system clipboard
25 bytes, looks like ansi escape
[alarm] offset 101 — terminal command (OSC): attaches a hyperlink to the text that follows
27 bytes, looks like ansi escape
[alarm] offset 144 — terminal command (OSC): attaches a hyperlink to the text that follows
7 bytes, looks like ansi escape
* [alarm] offset 176 — carriage return overwrites 24 character(s) of this line
stored=npm install --production\r echo "safe"
displayed= echo "safe"--production
[notice] offset 69 — ESC[0m — colour or text attribute
4 bytes, looks like ansi escape
* not removable — reported and left in placeReported by what each sequence does rather than by its bytes. The last is not an escape at all: a carriage return mid-line, so the command stored and the command displayed are different text, and augur prints both.
Why a file worth printing is worth scanning
Install instructions get read in a terminal and pasted into a shell. A concealed segment, a link whose text need not resemble its target, and a clipboard write are all one cat away.
OSC 52 is the one to know: it writes your system clipboard. What you paste next is not necessarily what you copied.
$curl -fsSL https://raw.githubusercontent.com/dejo1307/augur/main/install.sh | shRelated:Scanning a repositoryTrojan Source and bidi overrideseverything it looks for