abusing-shadow-credentials-for-privesc

Fail

Audited by Socket on Aug 3, 2026

1 alert found:

Malware
MalwareHIGH
scripts/agent.py

This module is a high-confidence offensive orchestration wrapper for Active Directory shadow credentials/Key Credential injection. It delegates the actual exploitation mechanics to external tools, then parses and prints recovered authentication material (NT hash and PFX password) and emits follow-on commands that embed secrets. Additionally, it executes a user-supplied local Python script path without integrity verification, creating an arbitrary code execution risk if the path is untrusted. No evidence of covert exfiltration over the network exists in this snippet, but the intended outcome (credential theft/account compromise) and direct secret disclosure make the security risk extreme for a “dependency” context.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Aug 3, 2026, 06:03 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fabusing-shadow-credentials-for-privesc%2F@17855641660e1e6bf5f8c9ec222bfdc26f3fb9be6ac9f9b96df15b2d38a9b445
Security Audit — socket — abusing-shadow-credentials-for-privesc