java-deserialization-methodology

Fail

Audited by Socket on May 16, 2026

2 alerts found:

Malwarex2
MalwareHIGH
references/ysoserial-gadgets.md

The provided content is a highly actionable, attacker-oriented exploit instruction set for Java deserialization (ysoserial gadget chains), including an out-of-band URLDNS vulnerability check and subsequent remote command execution guidance (e.g., reading '/flag.txt') delivered via HTTP cookies/bodies or WebLogic T3. This is consistent with malicious intent and would be unsafe to include as part of a software supply chain.

Confidence: 80%Severity: 100%
MalwareHIGH
references/jndi-fastjson.md

This fragment is attacker-oriented exploitation material for multiple high-impact Java/JVM vulnerabilities, explicitly describing RCE and sensitive file read payloads with attacker-controlled LDAP/RMI/HTTP callbacks and version-specific Fastjson/Shiro gadget chains, plus delivery to JBoss/Jenkins/WebLogic endpoints. If included in a software supply chain artifact, it would be consistent with malicious tooling or a compromise playbook rather than benign functionality.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
May 16, 2026, 10:42 AM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fjava-deserialization-methodology%2F@a2b061703d60c8f810023d8eb908a0cc03a94ea3
Security Audit — socket — java-deserialization-methodology