network-poisoning-attack
Audited by Socket on Jun 16, 2026
3 alerts found:
SecurityMalwarex2This fragment is unequivocally an offensive MITM and credential-interception/relay playbook. It instructs ARP/DHCP/DHCPv6 poisoning, DNS/WPAD injection, traffic redirection (iptables/bettercap), optional ICMP redirect routing changes, and orchestration of NTLM relay/capture tooling. If present in a software supply-chain dependency, it represents extreme malicious intent and should be treated as a high-risk/unsafe artifact.
This provided fragment is not benign software code; it is an explicit, highly operational intrusion/poisoning playbook focused on ADIDNS/DNS/WPAD manipulation, credential capture/relay, DNS spoofing/mitm setups, and WSUS poisoning to achieve remote command execution. While there is no actual library/module logic here to analyze for runtime malware, the content itself is strongly indicative of malicious intent and would be unacceptable in a legitimate software supply chain.