mongodb-attack

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

该技能与“攻击/利用”目的完全一致,但其能力本身是高风险的进攻性安全操作:扫描、爆破、未授权访问、NoSQL 注入、数据导出与提权均会对外部目标产生直接影响。未见明显供应链或凭据转发陷阱,因此更像高风险攻击技能而非伪装窃密器;总体应归为高风险、可被滥用的漏洞利用技能。

Confidence: 94%Severity: 90%
MalwareHIGH
references/attack-techniques.md

This fragment is not benign library code; it is a MongoDB attack/intrusion guide demonstrating exploitation of server-side JavaScript execution (db.eval, $where, mapReduce), permission escalation to root, and sensitive data extraction (system users/GridFS) plus credential harvesting. These are strong indicators of malicious intent. No actual npm dependency code was provided beyond this attack-oriented snippet, so the analysis is limited to what’s present.

Confidence: 90%Severity: 90%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fmongodb-attack%2F@14aa33ca410f1e1e193f5345f1b012735a9cb504bff934e13c0d33eb72b70e2f
Security Audit — socket — mongodb-attack