tsinghua-graduate-thesis

Fail

Audited by Socket on Aug 24, 2026

1 alert found:

Malware
MalwareHIGH
scripts/tests/prepare-broken-poppler.py

The snippet performs deliberate dependency sabotage: it copies the system libpoppler used by pdftoppm and binary-patches an embedded Poppler data directory (/usr/share/poppler) to a placeholder (/missing/poppler). This is highly likely to break or disable PDF rendering/conversion at runtime, and the use of /opt/broken-poppler naming strongly suggests an intentional “poisoned” artifact rather than benign maintenance. No direct network exfiltration or credential theft is present in this fragment; the primary risk is integrity/availability impact and potential preparation for later dependency hijacking via other components not shown here.

Confidence: 78%Severity: 90%
Audit Metadata
Analyzed At
Aug 24, 2026, 05:01 PM
Package URL
pkg:socket/skills-sh/tiangong-ai%2Fskills%2Ftsinghua-graduate-thesis%2F@98c5cd21f52dafca40b2ed86af59a0e0acb6a1e5656f621cfab4d94d12dcce8b
Security Audit — socket — tsinghua-graduate-thesis