crypto-clipper-malware-detection
Fail
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python code for establishing system persistence by modifying the Windows Registry. It demonstrates how to add entries to 'Software\Microsoft\Windows\CurrentVersion\Run' to execute a malicious binary on system startup, masquerading as legitimate system processes like 'rdpclip'.
- [DATA_EXFILTRATION]: The skill contains functional logic for 'clipboard hijacking' where it polls the system clipboard, identifies cryptocurrency wallet addresses using regex patterns, and replaces them with attacker-controlled addresses. This technique is designed for the theft of digital assets during transaction initiation.
Recommendations
- AI detected serious security threats
Audit Metadata