security-webshells

Fail

Audited by Socket on Jun 14, 2026

5 alerts found:

Malwarex3Securityx2
MalwareHIGH
references/Web-Shells/FuzzDB/cmd.sh

The provided file is highly consistent with embedded web-shell/backdoor behavior. It takes attacker-controlled QUERY_STRING input, decodes it into an executable payload, and then directly executes that payload using eval ($VALUE). Additional eval usage and risky utility/path resolution further amplify exploitability. This should be treated as malicious and not used as-is.

Confidence: 60%Severity: 90%
SecurityMEDIUM
references/Web-Shells/FuzzDB/up.sh
SecurityMEDIUM
references/Web-Shells/FuzzDB/list.sh
MalwareHIGH
references/Web-Shells/CFM/shell.cfm.html

This fragment is best characterized as a malicious server-side webshell/backdoor. It enables arbitrary OS command execution and file upload to the server (with planting potential) and it performs credential harvesting by decrypting and returning ColdFusion datasource passwords in the HTTP response. Treat as critically dangerous; assume compromise potential and remove/deny access immediately, then investigate for persistence and exfiltration.

Confidence: 60%Severity: 90%
MalwareHIGH
references/Web-Shells/Vtiger/README.md

Based on the provided module description and example endpoint, this extension is intended to enable remote OS command execution on the Vtiger web server via attacker-controlled HTTP parameters. Even without the implementation code, the documented behavior matches a webshell/RCE backdoor pattern and presents an extreme security risk if obtained or installed.

Confidence: 60%Severity: 90%
Audit Metadata
Analyzed At
Jun 14, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/Eyadkelleh%2Fawesome-skills-security%2Fsecurity-webshells%2F@dbfb09400c1c0e93b1eebcf561bb383df71e7caec91f82e9e0f3ebb527e7925a
Security Audit — socket — security-webshells