ghidra-headless-frida-runtime-injection
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalyfrida-scripts/decomp-compare.js
LOWAnomalyLOW
frida-scripts/decomp-compare.js
This module is a Frida instrumentation script intended for reverse-engineering/compare workflows: it dynamically hooks configured targets and reports enter/leave events, including function return values, to the Frida controller. There is no direct evidence of overt malware (no persistence or system/network actions in this snippet), but the design inherently enables intrusive observation and potential sensitive data disclosure if the configuration or controller is compromised/misused.
Confidence: 63%Severity: 52%
Audit Metadata