Skip to content
augur

What it finds

ANSI escape sequences in files you print

Some bytes in a file are not characters a terminal prints. They are instructions it carries out, the moment you cat, less or grep the file.

ESC[8m concealOSC 52 clipboard writeOSC 8 hyperlinkterminal injection

What each one does, spelled out

$ augur scan install.sh
install.sh (text): 6 finding(s)

TERMINAL
   [alarm] offset 39 — ESC[8m — conceal: hides the text that follows
       4 bytes, looks like ansi escape
   [alarm] offset 75 — terminal command (OSC): writes to the system clipboard
       25 bytes, looks like ansi escape
   [alarm] offset 101 — terminal command (OSC): attaches a hyperlink to the text that follows
       27 bytes, looks like ansi escape
   [alarm] offset 144 — terminal command (OSC): attaches a hyperlink to the text that follows
       7 bytes, looks like ansi escape
 * [alarm] offset 176 — carriage return overwrites 24 character(s) of this line
       stored=npm install --production\r echo "safe"
       displayed= echo "safe"--production
   [notice] offset 69 — ESC[0m — colour or text attribute
       4 bytes, looks like ansi escape

* not removable — reported and left in place

Reported by what each sequence does rather than by its bytes. The last is not an escape at all: a carriage return mid-line, so the command stored and the command displayed are different text, and augur prints both.

Why a file worth printing is worth scanning

Install instructions get read in a terminal and pasted into a shell. A concealed segment, a link whose text need not resemble its target, and a clipboard write are all one cat away.

OSC 52 is the one to know: it writes your system clipboard. What you paste next is not necessarily what you copied.

$curl -fsSL https://raw.githubusercontent.com/dejo1307/augur/main/install.sh | sh

Related:Scanning a repositoryTrojan Source and bidi overrideseverything it looks for