workers-app-tester
Fail
Audited by Socket on May 11, 2026
1 alert found:
MalwareMalwarescripts/bypass.js
HIGHMalwareHIGH
scripts/bypass.js
This module is strongly indicative of malicious/abusive intent for intercepting HTTPS traffic: it installs Frida runtime hooks that disable certificate validation and SSL pinning across multiple Android networking stacks (TrustManager/Conscrypt/OkHttp/SSLContext/WebView/Apache) and additionally forces cleartext traffic allowance. While the snippet does not show credential theft or network exfiltration directly, it materially enables MITM-style interception by weakening transport security. Treat as high risk and do not deploy in production environments.
Confidence: 90%Severity: 100%
Audit Metadata