network-poisoning-attack

Fail

Audited by Socket on Jun 16, 2026

3 alerts found:

SecurityMalwarex2
SecurityMEDIUM
SKILL.md
MalwareHIGH
references/layer2-poisoning.md

This fragment is unequivocally an offensive MITM and credential-interception/relay playbook. It instructs ARP/DHCP/DHCPv6 poisoning, DNS/WPAD injection, traffic redirection (iptables/bettercap), optional ICMP redirect routing changes, and orchestration of NTLM relay/capture tooling. If present in a software supply-chain dependency, it represents extreme malicious intent and should be treated as a high-risk/unsafe artifact.

Confidence: 60%Severity: 90%
MalwareHIGH
references/name-resolution-poisoning.md

This provided fragment is not benign software code; it is an explicit, highly operational intrusion/poisoning playbook focused on ADIDNS/DNS/WPAD manipulation, credential capture/relay, DNS spoofing/mitm setups, and WSUS poisoning to achieve remote command execution. While there is no actual library/module logic here to analyze for runtime malware, the content itself is strongly indicative of malicious intent and would be unacceptable in a legitimate software supply chain.

Confidence: 60%Severity: 90%
Audit Metadata
Analyzed At
Jun 16, 2026, 03:14 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fnetwork-poisoning-attack%2F@6ba5b524c164438b1cc9e96f6b6c396cfeab7c6a51565b638a8e476bacfc68cd
Security Audit — socket — network-poisoning-attack