mcpwn
Audited by Socket on Sep 5, 2026
3 alerts found:
SecurityMalwarex2SUSPICIOUS. The skill is internally aligned with offensive security and debugging, but its footprint is inherently high risk: sudo-capable command execution, tunnels, shells, remote file transfer, and transcript preservation of sensitive findings. The biggest concern is trust: the MCPwn/NeuroMatrix ecosystem described here is not publicly verifiable from official same-org sources, so users are asked to rely on an opaque security-tool runtime with broad execution and data-movement powers.
The fragment is overtly intrusion-oriented and describes complete capabilities for establishing C2 reachability (VPN/expose/forward), performing SOCKS pivoting (chisel/ssh + proxychains), receiving reverse shells (penelope/nc with PTY handling), delivering staged payloads, and maintaining persistence via systemd-run—plus Windows/AD/Kerberos post-exploitation workflows and firewall weakening guidance. Even without code-level verification of hidden behavior, the described operational actions are high-impact and consistent with malware/backdoor tooling. Treat the containing package as extremely high risk and subject it to deep static/dynamic analysis for any embedded executables, payload loaders, or runtime networking/credential-handling logic.
The fragment describes an end-to-end agent workflow that (a) downloads artifacts over an HTTP CAS data plane and (b) stages and uploads a curated set of offensive/credential-theft and post-exploitation tools to remote hosts via SMB/other protocols, including explicit pass-the-hash authentication and remote path placement suitable for execution. This is highly indicative of intrusion-enabling capability rather than benign analysis-only functionality. While the exact implementation details are not fully visible, the operational content and explicit abuse mechanisms (credential dumping tooling + pass-the-hash + remote staging) make the security risk extremely high in a supply-chain context.