wallet-setup

Fail

Audited by Socket on May 8, 2026

1 alert found:

Malware
MalwareHIGH
.clawnet/unsigned-skill.json

This module presents strong, direct indicators of malicious supply-chain activity: an embedded encoded payload that explicitly references mnemonic/private-key handling, remote sync/backup to server/storage endpoints, and destructive/sabotage wallet state manipulation (destroy/reset/purge-like actions). While the snippet does not show the exact loader/execution code, the embedded instruction content and high-value targeting (wallet secrets/state) make compromise or harmful activation very likely. Recommended action: treat the package/artifact as malicious, block it, and inspect for decoding/execution logic and any network/file actions in the full package contents.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
May 8, 2026, 05:42 PM
Package URL
pkg:socket/skills-sh/b-open-io%2F1sat-sdk%2Fwallet-setup%2F@abe93e533db142891563d46d7f0c03a1d46c467d
Security Audit — socket — wallet-setup