tsinghua-graduate-thesis
Fail
Audited by Socket on Aug 24, 2026
1 alert found:
MalwareMalwarescripts/tests/prepare-broken-poppler.py
HIGHMalwareHIGH
scripts/tests/prepare-broken-poppler.py
The snippet performs deliberate dependency sabotage: it copies the system libpoppler used by pdftoppm and binary-patches an embedded Poppler data directory (/usr/share/poppler) to a placeholder (/missing/poppler). This is highly likely to break or disable PDF rendering/conversion at runtime, and the use of /opt/broken-poppler naming strongly suggests an intentional “poisoned” artifact rather than benign maintenance. No direct network exfiltration or credential theft is present in this fragment; the primary risk is integrity/availability impact and potential preparation for later dependency hijacking via other components not shown here.
Confidence: 78%Severity: 90%
Audit Metadata