Injected Code — Unauthorized Remote Access (SSH Key Backdoor / Tunnel / Port Forward) - ATR-2026-01899 (b2286a9e-9cf4-5cf7-b28c-bd75c0cd95d7)
Detects injected code that establishes a persistent or interactive backdoor: appending a remote-fetched key to ~/.ssh/authorized_keys, opening an interactive SSH local-forward tunnel via pexpect, or building a socket port-forward bridge from a local listener to a remote host.