operating-havoc-c2
Audited by Socket on Aug 7, 2026
3 alerts found:
SecurityMalwarex2High-risk offensive security skill. Its install path is mostly coherent and same-project, but the actual capability set is a full AI-operable C2/post-exploitation workflow with evasive payloads, in-memory execution, and pivoting, making it unsuitable as a low-risk skill even without evidence of hidden credential theft or deceptive third-party routing.
This Python helper is highly aligned with offensive command-and-control deployment: it scaffolds a Havoc Yaotl teamserver profile containing Demon Injection/spawn configuration and can build and launch the Havoc server binary with that profile. While it contains no obfuscated payload or direct exfiltration in this snippet, it meaningfully enables C2 setup and execution. Treat as high-risk in a software supply chain context, especially when build directories/binaries/profiles are not fully trusted.
This material is high-confidence, high-risk supply-chain content because it documents operation of a C2 framework with explicit capabilities commonly associated with malware: in-memory execution, shellcode/process injection, file transfer/deletion, and network pivoting via SOCKS and reverse port forwarding, alongside evasion-oriented configuration options. Even though it is documentation rather than executable code, distributing or bundling such content in an otherwise benign package would be a major red flag.