conducting-spearphishing-simulation-campaign

Fail

Audited by Socket on Apr 17, 2026

1 alert found:

Malware
MalwareHIGH
references/workflows.md

This document is a high-confidence malicious spearphishing playbook. It contains step-by-step instructions to create phishing infrastructure, craft convincing emails and landing pages to harvest credentials, deliver and execute malware payloads (HTML smuggling, macros, ISO/LNK chains), and evade defenses (SPF/DKIM/DMARC, SSL, typosquatting, obfuscation). It explicitly instructs capturing passwords and setting up C2/callbacks. This content should be treated as malicious operational guidance and not used in production; hosting or executing any of these steps would facilitate targeted compromise. Recommend immediate removal/blocking, reporting to relevant abuse channels, and further investigation of any artifacts or domains used.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Apr 17, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fconducting-spearphishing-simulation-campaign%2F@93d89ade0b33c214197cf3fa036c0ca336ce1b14