This page is loaded when the malicious preinstall script runs on the victim CI/CD machine. In a real attack, the attacker would receive: hostname, username, env vars, AWS credentials.