macos-process-injection
Audited by Socket on Jul 21, 2026
2 alerts found:
MalwareSecurityThis fragment is a clearly malicious exploitation methodology/playbook. It provides explicit instructions and code for executing payloads (dylib constructor + system(), Electron/Node execSync, CDP Runtime.evaluate) and for high-impact exploitation (Mach task injection, Mach bootstrap squatting, XPC privileged interaction). While not typical npm dependency code, its presence in any package would represent a severe supply-chain security risk.
SUSPICIOUS/HIGH-RISK skill. The footprint is coherent with its stated purpose, but that purpose is to provide offensive macOS process-injection techniques, including escalation and bypass-adjacent routing. No clear credential theft or hidden exfiltration is present, and install trust issues are limited, but the skill materially enables exploitation and should be treated as a high-risk offensive capability rather than a benign developer aid.