impacket

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

The install instructions are largely consistent with the official Impacket project, so supply-chain concern is limited to unpinned source installation. The primary issue is scope: this skill is an offensive penetration-testing/attack skill for AD environments, enabling credential theft, lateral movement, and privilege escalation. That makes it high risk for AI-agent use, but not confirmed malware.

Confidence: 95%Severity: 86%
MalwareHIGH
references/relay-and-delegation-internals.md

The provided fragment is overwhelmingly indicative of malicious offensive behavior: an Active Directory Kerberos delegation abuse and credential-dumping playbook. It uses attacker-controlled secrets, manipulates Kerberos credential caches (KRB5CCNAME), performs impersonation to service SPNs, and then dumps credentials from a domain controller using Kerberos tickets, replication-based methods, or NTDS/snapshot extraction (shadow copy + SYSTEM hive export). If such content were present in a dependency, it would represent a critical supply-chain security red flag rather than legitimate software functionality.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fimpacket%2F@12e6b658f79535206da1ddd85132bab769a4802eff6ecc3c9349e36c0368c01a
Security Audit — socket — impacket