cross-attack-chains

Fail

Audited by Socket on Jul 31, 2026

1 alert found:

Malware
MalwareHIGH
references/exploit-chains-template.md

The provided content is unequivocally adversarial exploit/PoC material, not legitimate dependency code. It demonstrates harvesting sensitive data from authenticated WordPress REST endpoints (users, WooCommerce, Gravity Forms, and SolidWP email/log/SMTP data), acquiring/persisting access via REST Application Passwords, and directly exfiltrating results to an attacker-controlled domain. It also includes a potential xmlrpc pingback SSRF/scan vector. If any of this logic appeared inside a software dependency, it would constitute extremely high supply-chain security risk.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fcross-attack-chains%2F@b2195141ea0c9086f3b51c648954aa31b8b49de9115c864081a4e85c91f94117
Security Audit — socket — cross-attack-chains