lov-wxmp-cracker
Audited by Socket on Aug 24, 2026
2 alerts found:
Obfuscated FileAnomalySUSPICIOUS: the wrapper’s stated purpose is plausible and the install path appears to be official Lovstudio tooling, but the real skill is delivered as encrypted private content and decrypted at runtime by a separate helper. That makes capability scope and data flows unverifiable, creating medium supply-chain and transitive-trust risk without enough evidence to call it malicious.
This fragment provides only an encrypted package manifest with AES-256-GCM metadata for referenced files; it contains no inspectable executable logic. While suspicious naming (“cracker”) and encrypted payloads reduce auditability and raise concern, there is insufficient evidence here to confirm malware, data theft, backdoors, or network exfiltration. A definitive assessment requires the decrypted contents of the referenced Python scripts and any loader/decryption mechanism.