cred-spray

Fail

Audited by Socket on May 9, 2026

2 alerts found:

Malwarex2
MalwareHIGH
evals/evals.json

This JSON fragment is an attack-enabling instruction set for credential spraying and pass-the-hash. It embeds plaintext credential material (an NTLM hash and example passwords) and elicits actionable outputs: lockout-evasion timing, concrete subnet-wide PTH command guidance (crackmapexec-like), and follow-on password candidate generation from stolen credential patterns. While it is not runtime malware code, its purpose is clearly offensive and directly operationally harmful, warranting treatment as a malicious supply-chain artifact/instruction payload.

Confidence: 90%Severity: 88%
MalwareHIGH
SKILL.md

该技能并非普通运维或审计辅助,而是专门为 AI 代理提供凭据喷洒、密码复用、PTH/PTK 和横向移动能力。能力范围与攻击目标完全一致,包含凭据聚合、批量认证尝试、锁定规避和高价值目标优先级,属于高风险进攻性安全技能;虽未见明显混淆或第三方窃密端点,但整体应判定为恶意/高危用途。

Confidence: 96%Severity: 97%
Audit Metadata
Analyzed At
May 9, 2026, 08:28 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fcred-spray%2F@4d8ae8b50a7d6c1e0afac15d226c73e164553b10
Security Audit — socket — cred-spray