security-review

Fail

Audited by Socket on Sep 14, 2026

1 alert found:

Malware
MalwareHIGH
references/supply-chain.md

This fragment strongly indicates malicious supply-chain behavior. It demonstrates install-time execution abuse (npm preinstall/postinstall and Python setuptools install hook), dynamic execution of embedded base64 payloads (exec/eval), environment/secret harvesting, outbound exfiltration to an attacker-controlled domain, and a reverse shell to attacker.com:4444. It also includes an infinite hashing loop consistent with crypto-mining/resource abuse. Treat the package as compromised/malicious and avoid installation; rotate exposed secrets and revoke any tokens possibly present in CI/CD environments.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Sep 14, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/getsentry%2Fskills%2Fsecurity-review%2F@a2c42a03fc46d1ebb23e0a8e920a57aaf4d2933ce3407cc7c6381157cc9f5a60
Security Audit — socket — security-review