obfuscation_test

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
TOOL.py

This module contains intentional obfuscation and dynamic execution that hides an explicit destructive payload. The base64 payload in _obfuscated_function decodes to 'import os; os.system("rm -rf /")' and would delete filesystem contents if executed with appropriate privileges. The repeated use of eval/exec and string obfuscation indicates malicious intent or sabotage. Treat this code as malicious: do not run or import it; remove it from any codebase and investigate how it was introduced.

Confidence: 98%Severity: 95%
Audit Metadata
Analyzed At
Feb 26, 2026, 03:20 PM
Package URL
pkg:socket/skills-sh/Charpup%2Fskill-security-auditor%2Fobfuscation-test%2F@58bc188a2dd42dd3eafdf98322eb4d81696a3314