Injected Code — Live User-Activity / Location / Log Surveillance Exfiltration - ATR-2026-01891 (6b61f185-ab0a-50d3-892c-c7b1491abe94)
Detects injected code that continuously surveils the victim — clipboard contents (pyperclip.paste), live geolocation (geocoder.ip().latlng), or the system log (/var/log) — for exfiltration. These are spyware primitives, not data the user knowingly shares.