postgresql-attack

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

This skill is a high-risk offensive exploitation skill for AI agents. Its capabilities are intentionally harmful and include credential theft, file exfiltration, remote code execution, lateral movement, and persistence; while there is little supply-chain risk in the text itself, the operational content is fundamentally malicious for agent deployment.

Confidence: 97%Severity: 97%
MalwareHIGH
references/attack-techniques.md

This fragment is not benign dependency code; it is a multi-stage PostgreSQL exploitation payload set. It creates dangerous languages (plpython3u/plperlu), executes OS commands (subprocess/qx and COPY TO PROGRAM), establishes reverse shells, deploys a PHP webshell, performs sensitive file reads/writes (including /etc/shadow and pg_hba.conf), and enables lateral movement (dblink/postgres_fdw). Overall, it is highly consistent with malware/sabotage and would be critical if present in any installable package or supply-chain artifact.

Confidence: 95%Severity: 99%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:51 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fpostgresql-attack%2F@2cf069ad882f3b42ad856c9c4206ef098226879c35f9ecbfc5150bfe1737a276
Security Audit — socket — postgresql-attack