slack-explorer

Fail

Audited by Socket on Mar 26, 2026

1 alert found:

Malware
MalwareHIGH
scripts/slack/extract-tokens.js

This script actively extracts Slack authentication secrets from the host (Keychain and Cookies DB), decrypts them, and uses them to obtain API tokens; it then prints these sensitive tokens to stdout. Functionally it is a credential-harvesting tool for Slack on macOS. If used by an attacker or included in a package without clear intent and user consent, it poses a serious privacy and security risk. There is no obfuscation, but the behavior is clearly invasive. Recommend not running this on systems you do not control or trust and treat any package containing this code as high-risk for credential theft.

Confidence: 90%Severity: 90%
Audit Metadata
Analyzed At
Mar 26, 2026, 11:31 PM
Package URL
pkg:socket/skills-sh/delexw%2Fclaude-code-misc%2Fslack-explorer%2F@cc785d10a44920c3b2cb94ea0756e0c40927d180