wireless-technique
Audited by Socket on Sep 5, 2026
5 alerts found:
Securityx3Malwarex2HIGH risk offensive security skill. Its capabilities are aligned with its stated purpose, but that purpose is to perform wireless credential capture, rogue-AP attacks, and direct access operations with real-world impact. Not confirmed malware, yet clearly unsuitable as a benign helper skill and dangerous to grant an AI agent.
This fragment is highly malicious and implements a complete Wi‑Fi credential theft (evil twin) workflow. It uses deauthentication to coerce victim reconnection, rogue AP impersonation, DNS/HTTP(S) redirection to a captive portal, and server-side persistence of user-submitted Wi‑Fi passwords to a local file. It also captures WPA2-Enterprise MSCHAPv2 credential material via hostapd-wpe/eaphammer and includes offline cracking steps. No meaningful benign or defensive software behavior is present in the provided fragment.
No supply-chain malware is evident because the fragment is not a library implementation—it's an offensive command workflow. Still, the actions explicitly enable credential interception/recovery (including active deauthentication/injection, PMKID/handshake/WEP material extraction, and hashcat cracking), which is high-risk and likely illegal/abusive without explicit authorization. Treat as a capability enabling unauthorized access rather than a safe dependency.
The fragment is an explicit, highly actionable offensive guide for sub-GHz and LoRaWAN exploitation, including RF capture/replay, ABP key recovery from firmware, node spoofing, forged downlink/command injection, and replay of captured uplinks when frame counters are weak/disabled. It is not obfuscated and contains no software dependency behavior to audit, but its content would materially facilitate unauthorized access, telemetry manipulation, and potentially real-world device control. Treat as high-risk malicious material.
This artifact is not a benign or defensive dependency; it is an offensive, step-by-step attack playbook for Zigbee/Thread/Matter. It includes explicit default cryptographic key material for decrypting join/transport exchanges, prescribes commissioning abuse, and describes replay/injection workflows that can lead to unauthorized control and persistent access. No executable package malware logic exists in the snippet, but the content itself is high-risk misuse material and should be treated as unsafe from a supply-chain/documentation distribution perspective.