impacket
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityMalwareThe install instructions are largely consistent with the official Impacket project, so supply-chain concern is limited to unpinned source installation. The primary issue is scope: this skill is an offensive penetration-testing/attack skill for AD environments, enabling credential theft, lateral movement, and privilege escalation. That makes it high risk for AI-agent use, but not confirmed malware.
The provided fragment is overwhelmingly indicative of malicious offensive behavior: an Active Directory Kerberos delegation abuse and credential-dumping playbook. It uses attacker-controlled secrets, manipulates Kerberos credential caches (KRB5CCNAME), performs impersonation to service SPNs, and then dumps credentials from a domain controller using Kerberos tickets, replication-based methods, or NTDS/snapshot extraction (shadow copy + SYSTEM hive export). If such content were present in a dependency, it would represent a critical supply-chain security red flag rather than legitimate software functionality.