cross-attack-chains
Fail
Audited by Socket on Jul 31, 2026
1 alert found:
MalwareMalwarereferences/exploit-chains-template.md
HIGHMalwareHIGH
references/exploit-chains-template.md
The provided content is unequivocally adversarial exploit/PoC material, not legitimate dependency code. It demonstrates harvesting sensitive data from authenticated WordPress REST endpoints (users, WooCommerce, Gravity Forms, and SolidWP email/log/SMTP data), acquiring/persisting access via REST Application Passwords, and directly exfiltrating results to an attacker-controlled domain. It also includes a potential xmlrpc pingback SSRF/scan vector. If any of this logic appeared inside a software dependency, it would constitute extremely high supply-chain security risk.
Confidence: 90%Severity: 95%
Audit Metadata