ultimate-browsing

Fail

Audited by Socket on Sep 27, 2026

4 alerts found:

Anomalyx2SecurityMalware
AnomalyLOW
scripts/extract_cookies.py

This is a browser-cookie extraction and optional local session-injection utility. It handles authentication cookies that could be used for account access, but this file shows no remote exfiltration or concealed behavior. The supplied code is syntactically incomplete at the CDP script assignment, so the injection implementation cannot be verified and the module will not run as shown.

Confidence: 98%Severity: 62%
AnomalyLOW
engine/tests/fixtures/search_interstitial.html

This module does not show clear classic malware (no overt credential theft, command execution, persistence outside cookies, or reverse-shell behavior in the excerpt). However, it strongly exhibits supply-chain-relevant telemetry behavior: it collects navigation/performance and error/context data, persists a session cookie (SG_SS), and transmits the constructed data to server endpoints via sendBeacon and Image-based fallbacks. Additionally, it includes a high-suspicion dynamic script-creation/eval-capable primitive, though the shown logic does not conclusively demonstrate attacker-driven execution. Net assessment: medium privacy/security risk due to network telemetry exfiltration patterns and audit difficulty; review/allowlisting and confirmation of expected provenance are recommended.

Confidence: 55%Severity: 60%
SecurityMEDIUM
references/insane-search/tls-impersonate.md

This fragment provides concrete automation logic and integration guidance for bypassing WAF/bot protections by impersonating browser TLS/transport fingerprints, spoofing navigation headers (Referer) and maintaining session state, detecting challenge markers in responses, and—most critically—injecting clearance cookies obtained from a real browser challenge solver into curl_cffi to access protected endpoints (including APIs). No clear indicators of classic malware (e.g., command execution or direct data theft code) are present in the snippet, but the capability is strongly usable for security-control circumvention and unauthorized access. Treat as high misuse/security risk for supply-chain contexts.

Confidence: 70%Severity: 86%
MalwareHIGH
scripts/cookie_crypto.py

This code fragment is a high-risk component that recovers OS-protected Chromium/Chrome master keys (DPAPI, Keychain, Secret Service) and decrypts Chromium v10/v11 encrypted values into plaintext. While no exfiltration is shown in this file, the implemented capability is directly consistent with browser credential/cookie/session theft workflows, making it very suspicious in a supply-chain context.

Confidence: 76%Severity: 88%
Audit Metadata
Analyzed At
Sep 27, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-openagent%2Fultimate-browsing%2F@51c1d89ff15bbb6aff7b7373899582c16f4ad11dc605d85858b3e5f54ce64be9