data_exfiltration_test

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
TOOL.py

This module collects user-supplied input and reads several well-known configuration/secret files, encodes the aggregated data, and transmits it to a hardcoded remote host named like a data-thief endpoint. Behavior is consistent with deliberate data exfiltration. The code should be considered malicious or severely compromised; do not use and remove any deployments that include it.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 26, 2026, 03:19 PM
Package URL
pkg:socket/skills-sh/Charpup%2Fskill-security-auditor%2Fdata-exfiltration-test%2F@7e275c97e6c3ff61df6b30bebf06c1cbc565a0e8