# gitlab.hyva.io — **CLOSED 2026-08-10**

| | |
|---|---|
| Tier | A |
| Risk | green |
| Platform | gitlab (18.11.7 CE) |
| Company | Hyvä |
| Country | FI |
| Sector | ecommerce/Magento |
| Source | WingsCloud ULP AUG-06 (AUG-06-21), channel "Wings Daily Updates FREE" |
| IP | 168.119.186.254 |
| Server | nginx |
| **Outcome** | **CLOSED — negative result. Cred valid + Developer access, ZERO secrets on instance (L2 HEAD + L3 history, two independent sources). Hygiene good. Only state-changing MR-pipeline vector remained — declined (risk/reward).** |
| **Integrity** | INTEGRITY.sha256 over 9 core artifacts |

## L1 creds (no-masking)
```
user: nirajp
pw:   niraj@2345
```

## Validation method
L1 read-only: `POST <base>/oauth/token grant_type=password` (gitlab) /
`POST /api/login` (grafana) / argocd session — JSON 200 = VALID.
Validated 2026-08-07 (wingscloud_slim.py L1 stage).

## Identification
nirajp; Hyvä theme vendor

## Status (2026-08-10)
L2 + L3 + L4 read-only COMPLETE. Notes: L2-secrets-notes.md; log: OPLOG.md.
- L1 re-confirmed (creds NOT rotated). Developer-level on hyva-themes; Owner(50) of
  tridhya-tech group (EMPTY namespace — 0 projects/vars/subgroups, no value).
- L2 blob search 544/544: 0 live secrets. L3 history (trufflehog + git log -G,
  two independent sources): 0 secrets in HEAD AND history. Secrets EXHAUSTED.
- L4 read-only account surface: 24 PATs (22 active api+read_user→2027, values NOT
  API-recoverable), 0 SSH keys, email niraj.p@tridhyatech.com (Tridhya = Hyvä's
  India outsourcing partner). staging.hyva.io basic-auth: nirajp/niraj@2345 = 401
  (two-control verified, cred rejected).
- CI surface: 8/544 projects have .gitlab-ci.yml, 7 run jobs (runners cpx41/cpx62
  Hetzner). MR-trigger pipelines EXIST in hyva-docs (refs/merge-requests/*).

## Next steps (L4 state-changing — operator-gated, explicit "go" required)
- [ ] MR-pipeline CI-var exfil: fork/branch + MR to a CI-enabled project with a
      poisoned .gitlab-ci.yml that echoes env → would dump project CI vars IF
      maintainer merges/approves pipeline. State-changing + social-eng dependent.
      Risk: high detection (MR is visible to maintainers).
- [ ] Password-reuse wider: niraj@2345 on Tridhya infra (out-of-scope host) or
      other Hyvä services — staging rejected; demo/docs are anon-read.
- [ ] Privesc Developer→Maintainer: no API path (would need admin action).
- [x] ~~L1~~, ~~L2~~, ~~L3~~, ~~L4 read-only~~ — done 2026-08-10.
