mongodb-attack
Fail
Audited by Socket on Aug 12, 2026
2 alerts found:
Malwarex2MalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
该技能与“攻击/利用”目的完全一致,但其能力本身是高风险的进攻性安全操作:扫描、爆破、未授权访问、NoSQL 注入、数据导出与提权均会对外部目标产生直接影响。未见明显供应链或凭据转发陷阱,因此更像高风险攻击技能而非伪装窃密器;总体应归为高风险、可被滥用的漏洞利用技能。
Confidence: 94%Severity: 90%
Malwarereferences/attack-techniques.md
HIGHMalwareHIGH
references/attack-techniques.md
This fragment is not benign library code; it is a MongoDB attack/intrusion guide demonstrating exploitation of server-side JavaScript execution (db.eval, $where, mapReduce), permission escalation to root, and sensitive data extraction (system users/GridFS) plus credential harvesting. These are strong indicators of malicious intent. No actual npm dependency code was provided beyond this attack-oriented snippet, so the analysis is limited to what’s present.
Confidence: 90%Severity: 90%
Audit Metadata