rabbitmq-tactics

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

该技能是面向 AI 代理的 RabbitMQ 攻击与后渗透手册,核心功能包括弱口令攻击、消息窃取、外传、后门持久化、RCE 与痕迹规避。其真实能力与任何良性自动化帮助都不相称,应判定为恶意/高危技能。

Confidence: 97%Severity: 99%
MalwareHIGH
references/attack-techniques.md

This fragment is highly indicative of malicious intrusion/exfiltration and disruption against RabbitMQ. It describes authenticated Management API operations to configure persistent message forwarding to an attacker-controlled broker (Shovel/Federation), modify and republish message payloads (integrity compromise), purge/delete broker resources for DoS, and escalate using Erlang cookie-based remote command execution primitives (rpc/rabbitmqctl eval with os:cmd, including reverse-shell). If found inside any dependency/package, it should be treated as critical compromise material rather than legitimate software.

Confidence: 93%Severity: 100%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Frabbitmq-tactics%2F@7c2c17e13b1ff4d6a9a07b28ba94d63232d614bc23763463dbb971dbd69e6bb4
Security Audit — socket — rabbitmq-tactics