ghidra-headless-frida-runtime-injection

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
frida-scripts/decomp-compare.js

This module is a Frida instrumentation script intended for reverse-engineering/compare workflows: it dynamically hooks configured targets and reports enter/leave events, including function return values, to the Frida controller. There is no direct evidence of overt malware (no persistence or system/network actions in this snippet), but the design inherently enables intrusive observation and potential sensitive data disclosure if the configuration or controller is compromised/misused.

Confidence: 63%Severity: 52%
Audit Metadata
Analyzed At
Apr 1, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fghidra-headless%2Fghidra-headless-frida-runtime-injection%2F@1348d4ceb81aee98a4408af32e4ee49b75b86e08