Skip to content

Hide Navigation Hide TOC

Injected Code — Environment-Variable Exfiltration - ATR-2026-01892 (b3628353-f854-5862-8bee-beb149ccf007)

Detects injected code that reads process environment variables via subscript access (os.environ[...]) and POSTs them to a remote server. Environment variables routinely hold API keys, tokens and paths, so this is a direct secret-exfiltration vector. Distinguished from benign os.environ.get() reads by requiring the remote POST sink.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Injected Code — Environment-Variable Exfiltration - ATR-2026-01892 (b3628353-f854-5862-8bee-beb149ccf007) Agent Threat Rules 1
Injected Code — Environment-Variable Exfiltration - ATR-2026-01892 (b3628353-f854-5862-8bee-beb149ccf007) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1