kafka-attack

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

High-risk offensive skill. Its capabilities align with its stated purpose, but that purpose is explicit unauthorized access, credential theft, message exfiltration, and destructive manipulation of Kafka infrastructure. No strong malware indicators like stealth or third-party exfil endpoints appear, but this is a dangerous exploit skill for AI agents.

Confidence: 96%Severity: 96%
MalwareHIGH
references/attack-techniques.md

This fragment is an overt offensive Kafka ecosystem exploitation playbook. It outlines how to enumerate exposed Kafka/ZooKeeper/Schema Registry/Kafka Connect services, extract sensitive configurations (including credential-like materials), escalate or persist through ACL manipulation, sabotage schema compatibility, inject malicious Kafka Connect connectors (including file and database access patterns), inject malformed/oversized messages, and perform destructive actions such as topic/subject deletion and ZooKeeper metadata removal. No obfuscation is evident, and there is no dependency code logic shown; nevertheless, if this content is bundled within a software dependency/release, it represents a high security risk and strong malicious-intent signal.

Confidence: 82%Severity: 85%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:51 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fkafka-attack%2F@d59dc0042a2487a863735ed8a8f0c36a94d9891563fc27630d50b9232f5283b0
Security Audit — socket — kafka-attack