sliver-c2

Fail

Audited by Socket on Jun 16, 2026

5 alerts found:

Malwarex4Security
MalwareHIGH
references/pivoting-proxy.md

This fragment provides detailed, step-by-step operational instructions for using Sliver C2 to proxy and pivot through compromised hosts (port forwarding, SOCKS5/WireGuard SOCKS, TCP pivot, and Windows named-pipe pivot), deploy additional pivot implants, and run reconnaissance and post-exploitation tooling against internal networks using embedded credential examples. While the snippet is not executable library code, it is strongly indicative of malware/C2 use and substantially increases the ability to perform intrusion and lateral movement if packaged/distributed in a software supply chain.

Confidence: 60%Severity: 90%
MalwareHIGH
references/post-exploitation.md

This fragment is a clear operational description of malicious post-exploitation capabilities: remote command execution, process injection/migration and in-memory assembly execution, privilege escalation, LSASS and Kerberos credential theft, and surveillance (keylogging/screenshotting). If an open-source package dependency implements or integrates similar functionality, it should be treated as extremely high risk. No supply-chain package code is provided here—only adversary command usage—so confidence is moderate, but the capability set strongly indicates malicious intent.

Confidence: 60%Severity: 90%
MalwareHIGH
references/implant-generation.md

This fragment provides instructions to generate Sliver C2 implants/beacons, embedding attacker-chosen callback endpoints, covert transport selection, periodic beacon/reconnect behavior, and environment-based execution gating, with multiple deployment formats including Windows service packaging. The content is explicitly operational malware/C2 tooling guidance; no benign purpose is evidenced. Generated artifacts should be treated as high-risk malicious malware.

Confidence: 60%Severity: 90%
MalwareHIGH
references/c2-protocols.md

This fragment is highly indicative of malicious command-and-control deployment guidance: it instructs how to generate and run an implant with covert transports (mTLS/HTTPS, DNS tunneling with sandbox canary detection, and WireGuard tunneling), includes stealth features (static web camouflage, proxy-aware fallback), persistence/robustness (multi-endpoint reconnect logic), and even host DNS resolver tampering to support covert communication. Treat as an extreme supply-chain risk if present in a software dependency or distributed artifact.

Confidence: 60%Severity: 90%
SecurityMEDIUM
SKILL.md
Audit Metadata
Analyzed At
Jun 16, 2026, 03:15 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fsliver-c2%2F@1a01226b97639d4ed9fc63876e2209a2a5e54510cdb85a3c088c23fcac52b52b
Security Audit — socket — sliver-c2