kafka-attack
Audited by Socket on Aug 12, 2026
2 alerts found:
SecurityMalwareHigh-risk offensive skill. Its capabilities align with its stated purpose, but that purpose is explicit unauthorized access, credential theft, message exfiltration, and destructive manipulation of Kafka infrastructure. No strong malware indicators like stealth or third-party exfil endpoints appear, but this is a dangerous exploit skill for AI agents.
This fragment is an overt offensive Kafka ecosystem exploitation playbook. It outlines how to enumerate exposed Kafka/ZooKeeper/Schema Registry/Kafka Connect services, extract sensitive configurations (including credential-like materials), escalate or persist through ACL manipulation, sabotage schema compatibility, inject malicious Kafka Connect connectors (including file and database access patterns), inject malformed/oversized messages, and perform destructive actions such as topic/subject deletion and ZooKeeper metadata removal. No obfuscation is evident, and there is no dependency code logic shown; nevertheless, if this content is bundled within a software dependency/release, it represents a high security risk and strong malicious-intent signal.