heap-exploitation
Audited by Socket on Sep 15, 2026
3 alerts found:
Securityx2MalwareSUSPICIOUS. The skill’s content is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive heap-exploitation capability, including arbitrary write and code-execution techniques. Install-path risk is moderate rather than dominant: `how2heap` is coherent, while `heapinspect` provenance is questionable. No credential theft or exfiltration is shown, so this is not confirmed malware, but it is a high-risk offensive-security skill.
The provided fragment is highly actionable offensive guidance targeting glibc heap and stdio/loader internals to achieve memory corruption and potential control-flow hijacking (RCE-style outcomes). It contains no actual runtime package logic in the snippet, so direct malware execution cannot be confirmed from this fragment alone; however, embedding such weaponization material in a distributed dependency would be a serious supply-chain security concern. Further review of the full package is needed to determine whether it is merely documentation or whether install/runtime code uses these techniques to attack real systems.
The provided fragment is high-risk offensive exploit guidance targeting glibc stdio internals (FSOP). It explicitly describes paths to (a) leak memory by corrupting FILE output pointers, (b) perform arbitrary memory writes by corrupting stdin FILE buffer metadata, and (c) potentially gain code execution by forging vtable/function-pointer structures and triggering exit/cleanup flush paths. Even if it is only documentation/tooling, embedding such content in a distributed package/artifact would be concerning and warrants deep investigation of repository context, build scripts, and whether any of this logic is executed or dropped at install/runtime.