cred-spray
Fail
Audited by Socket on May 9, 2026
2 alerts found:
Malwarex2Malwareevals/evals.json
HIGHMalwareHIGH
evals/evals.json
This JSON fragment is an attack-enabling instruction set for credential spraying and pass-the-hash. It embeds plaintext credential material (an NTLM hash and example passwords) and elicits actionable outputs: lockout-evasion timing, concrete subnet-wide PTH command guidance (crackmapexec-like), and follow-on password candidate generation from stolen credential patterns. While it is not runtime malware code, its purpose is clearly offensive and directly operationally harmful, warranting treatment as a malicious supply-chain artifact/instruction payload.
Confidence: 90%Severity: 88%
MalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
该技能并非普通运维或审计辅助,而是专门为 AI 代理提供凭据喷洒、密码复用、PTH/PTK 和横向移动能力。能力范围与攻击目标完全一致,包含凭据聚合、批量认证尝试、锁定规避和高价值目标优先级,属于高风险进攻性安全技能;虽未见明显混淆或第三方窃密端点,但整体应判定为恶意/高危用途。
Confidence: 96%Severity: 97%
Audit Metadata