edr-evasion-dev
Audited by Socket on Sep 5, 2026
7 alerts found:
SecurityMalwarex6SUSPICIOUS: this skill is an offensive EDR-evasion and process-injection playbook for loaders/implants, giving an AI agent high-risk security/stealth capabilities with real-world abuse potential. I found no strong supply-chain abuse, but the skill’s core function is incompatible with benign agent assistance and squarely fits high-risk offensive security tooling.
This fragment is not a functional dependency; it is explicit malware tradecraft documentation for Windows injection/evasion techniques (remote memory write/execution, APC/thread hijacking, PPID spoofing, threadless DLL/EPI execution, and thread-pool callback hijacking). No actual executable logic is present here, but the intent and specificity indicate malicious operational guidance. If this appears inside a published package, it is a serious supply-chain red flag.
This fragment is an explicitly adversarial Linux EDR/XDR evasion and intrusion playbook. It provides actionable reconnaissance-to-action guidance to fingerprint eBPF/LSM/kprobe coverage and then execute stealthy fileless/in-memory execution, exploit io_uring observability gaps, interfere with security telemetry (including competing BPF/map manipulation and LKM/ftrace concepts), establish persistence, perform injection, and enable covert C2. Treat it as a strong supply-chain compromise indicator and a malicious operational artifact rather than benign documentation.
The provided content is not actual compilable library code; it is a highly specific adversary/operator memo describing Windows in-memory payload loading, process injection, syscall/VEH/ETW evasion, ntdll unhooking, and anti-analysis behaviors. These are strong malware indicators typical of offensive implants. Because the real implementation is not present in the excerpt, the analysis cannot confirm concrete data flows or exact code paths, but the described capabilities are critically concerning for any supply-chain dependency that contains or implements this behavior.
This fragment is not a benign dependency module; it is adversarial doctrine for building and operating stealthy loader/implant tooling that targets EDR/telemetry evasion on Windows and Linux, including staged enablement, signature minimization, and anti-analysis/testing guidance. Although the excerpt contains no executable logic, its explicit malicious operational intent and detailed capability-oriented instructions make the supply-chain risk high.
This fragment is high-risk attacker tradecraft guidance for anti-debug/anti-VM evasion and stealth execution. It specifies how to detect analysis environments, selectively trigger evasive branching, conceal static indicators (IAT/API/string hiding and late binding), and manipulate entropy/section placement to reduce ML/AV detection. No direct malicious execution is shown here, but the intent and techniques are strongly consistent with malware/loader development. Additional code context would be required to confirm that the referenced behaviors are actually implemented in the package.
This fragment describes a high-risk ETW-evading loader technique: temporary byte-stomping of ntdll’s NtTraceEvent and EtwEventWrite prologues using NtWriteVirtualMemory (self-target) to suppress telemetry during a short window, then restoring original bytes to evade integrity checks before handoff to longer execution. While actual implementational details are not present, the described intent and concrete patch-and-restore workflow are strongly consistent with malicious staging/stealth behavior.