performing-blind-ssrf-exploitation
Fail
Audited by Socket on Apr 12, 2026
1 alert found:
MalwareMalwarereferences/api-reference.md
HIGHMalwareHIGH
references/api-reference.md
The provided code is strongly indicative of malicious/offensive intent: it actively crafts SSRF probe requests, includes OOB callback confirmation infrastructure, performs blind timing-based detection, executes internal port scanning via SSRF, and supplies multiple SSRF bypass payload formats targeting high-value metadata and internal services. If included in a dependency, it represents a high misuse/security risk. Malware behavior (e.g., credential theft code) is not directly demonstrated, but the exploitation workflow is directly usable for credential/data exposure via SSRF.
Confidence: 80%Severity: 92%
Audit Metadata