macos-process-injection

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

MalwareSecurity
MalwareHIGH
DYLIB_XPC_TECHNIQUES.md

This fragment is a clearly malicious exploitation methodology/playbook. It provides explicit instructions and code for executing payloads (dylib constructor + system(), Electron/Node execSync, CDP Runtime.evaluate) and for high-impact exploitation (Mach task injection, Mach bootstrap squatting, XPC privileged interaction). While not typical npm dependency code, its presence in any package would represent a severe supply-chain security risk.

Confidence: 90%Severity: 95%
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. The footprint is coherent with its stated purpose, but that purpose is to provide offensive macOS process-injection techniques, including escalation and bypass-adjacent routing. No clear credential theft or hidden exfiltration is present, and install trust issues are limited, but the skill materially enables exploitation and should be treated as a high-risk offensive capability rather than a benign developer aid.

Confidence: 95%Severity: 88%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fmacos-process-injection%2F@42632d918eeb50bda281fdd32f85c6a5f5f2dae1fa9b27f5ab50b3646e1f89ca
Security Audit — socket — macos-process-injection