wx-cli
Audited by Socket on Sep 18, 2026
11 alerts found:
Securityx5Anomalyx5Malware该技能的功能与宣称目的基本一致:它确实是一个本地微信取证/查询工具,而非明显伪装的无关能力。但其核心风险很高:安装源是不可独立验证的私有仓库/私有发行物,且该黑盒 CLI 需要管理员权限、从微信进程内存提取数据库密钥,并可读取大量高度敏感的个人消息数据。未见明确外传端点,因此更像高风险/可疑技能而非确认恶意。
The fragment appears to implement a legitimate encrypted SQLite decryption and WAL-cache subsystem, with no evidence of intentional malware, data exfiltration, backdoors, or sabotage. It has a concrete path traversal risk because rel_key is not constrained to remain under db_dir. It also has a potentially serious arbitrary-path access and deletion issue if mtime_file can be modified, because persisted cache paths are trusted. Plaintext decrypted cache files require appropriate filesystem permissions. These issues should be fixed by validating rel_key, rejecting absolute paths and traversal components, canonicalizing and enforcing directory containment, and validating that persisted paths remain inside cache_dir before opening or deleting them.
The fragment is a purpose-built WeChat database key extraction tool, not general application logic. It performs privileged process-memory inspection and debugger-based cryptographic key capture, so running it grants substantial access to sensitive WeChat data and should be treated as high-impact security tooling. There is no evidence in this file of malware, network exfiltration, persistence, destructive behavior, or obfuscation. The main technical concerns are sensitive key handling, external-process execution, LLDB script injection/path quoting, and the correctness of manually declared Mach FFI interfaces.
This fragment documents a local WeChat decryption and data-extraction utility with extensive privileged access to process memory and sensitive local databases. Those capabilities create substantial privacy and local data-protection risk, especially because extracted keys and decrypted database caches are persisted. However, the visible text does not show malware indicators such as network exfiltration, remote control, credential harvesting unrelated to the stated function, destructive behavior, or cryptomining. Assessment is limited because only documentation is provided and the implementation is not visible.
This fragment is highly security-relevant and appears to enable unauthorized decryption and extraction of WeChat macOS local database contents. It provides actionable instructions to obtain SQLCipher keys directly from a running WeChat process (via Frida/task_for_pid or C memory scanning) and then decrypt/write plaintext SQLite databases. It also includes steps to weaken macOS code-signing protections (removing Hardened Runtime) to make process memory access possible. No code obfuscation is present; the risk stems from the capability to compromise confidentiality of a third-party application’s encrypted data.
The fragment is a local Windows memory-scanning implementation for recovering WeChat database encryption keys. It contains sensitive credential/key extraction behavior and relies on privileged process-memory access, but it shows no evidence of malware, network exfiltration, persistence, command execution, or obfuscation. The main risks are unauthorized use, exposure of extracted key material within the application, and possible resource cleanup issues on error paths not covered by this fragment.
This module is highly likely malicious/abusive: it opens and reads another process (Weixin.exe), scans its memory for strings that look like AES keys, and verifies recovered candidates against V2 templates, then returns the recovered AES key material. That is a classic key-extraction/data-theft pattern. While the code may be intended for interoperability or reverse engineering, from a supply-chain security perspective it enables unauthorized secret recovery from a third-party application and is therefore a strong security red flag.
This is a specialized WeChat database-key recovery scanner. It contains a significant privacy and security risk because it reads another process's memory and extracts potential encryption keys, but the fragment shows no exfiltration, persistence, destructive behavior, or obfuscation. Use should be restricted to authorized forensic or recovery contexts. Assessment of the exact key-pattern logic requires the omitted helper implementations.
The code is a conventional but weakly verified Windows installer. It contains no direct evidence of malware, credential theft, data exfiltration, reverse shells, or obfuscated payloads. However, executing it through irm|iex and installing an unpinned, unsigned, unchecked executable creates a meaningful supply-chain risk. Use a pinned release with verified SHA-256 checksum or Authenticode signature and review the script locally before execution.
This is a conventional remote binary installer, not overt malware. It downloads an unverified executable and installs it system-wide, potentially with sudo. The absence of checksum or signature verification creates a significant supply-chain integrity risk, although no direct data theft, persistence, or destructive behavior is present in the supplied script.
The postinstall script executes a local installer (install.js). This is a legitimate installation pattern but carries risk: install.js will run with the installer's privileges and could access and exfiltrate local WeChat data, phone backups, or other sensitive files, or perform other malicious actions (telemetry, remote code execution, installing further packages). Review the contents of install.js before installing or run the install in a sandboxed environment. The package metadata does not contain obviously malicious dependency URLs or overrides, but the runtime behavior depends entirely on install.js.