pptx
Audited by Socket on Sep 8, 2026
2 alerts found:
Anomalyx2A wrapper launches soffice and, when Unix sockets are unavailable, writes C source to a temporary file, compiles it with gcc, and injects the resulting shared library into soffice via LD_PRELOAD. This pattern enables arbitrary native code execution inside the trusted application. The exact payload source (_SHIM_SOURCE) is not provided in the available fragment, so the specific malicious behavior cannot be fully verified from the excerpt.
No clear evidence of intentional malware, tracking, credential theft, or network-based exfiltration in this fragment. The primary security weakness is use of zipfile.ZipFile.extractall(output_path) on an untrusted Office ZIP without validating member paths, enabling potential ZIP Slip/path traversal and arbitrary file write outside the chosen output directory. Additional risk could be introduced by the unseen DOCX helper functions, but that behavior is not assessable from this module alone.