shopify-admin

Fail

Audited by Socket on Sep 15, 2026

4 alerts found:

Obfuscated Filex3Anomaly
Obfuscated FileHIGH
assets/admin_2026-10.json.br

This fragment does not directly demonstrate malware because no observable sink or execution mechanism is present. However, the enormous binary-like string is strongly suspicious as an embedded or packed payload and substantially increases obfuscation concerns. The complete file should be reviewed for decoding, dynamic execution, filesystem changes, process spawning, or network exfiltration before use.

Confidence: 90%
Obfuscated FileHIGH
assets/admin_2026-07.json.br

The fragment is an opaque binary payload rather than analyzable source code. It provides no direct evidence of malicious behavior, but its unusually large and unreadable embedded data materially limits analysis and warrants inspection of the original file format, hashes, decoders/loaders, and any execution paths. The fragment alone should not be classified as malware.

Confidence: 90%
Obfuscated FileHIGH
assets/admin_2026-01.json.br

The shown portion is an opaque binary-like blob with no directly observable malicious behavior or security sink. Its encoding is anomalous for ordinary source code and prevents meaningful semantic review. The overall file cannot be cleared without identifying the blob format and examining the code that produces, decodes, executes, writes, or transmits it.

Confidence: 90%
AnomalyLOW
scripts/track-telemetry.ps1

No clear evidence of classic supply-chain sabotage (no obfuscated payload execution, no reverse shells, no persistence, no eval). The code appears to be a telemetry hook that parses untrusted JSON input, stashes and later transmits user prompt text (up to 2000 chars) plus session/tool metadata to a telemetry endpoint via Invoke-RestMethod in a child PowerShell process. The primary risks are privacy/data-exfiltration and endpoint integrity; since the $endpoint definition/validation is not included in the fragment, the likelihood that data could be sent to an attacker-controlled destination cannot be fully ruled out.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Sep 15, 2026, 06:46 AM
Package URL
pkg:socket/skills-sh/shopify%2Fshopify-ai-toolkit%2Fshopify-admin%2F@e194f5e2281f1f40d3fa9e2f2aeb70f3255be196603621d1bbc48f7d38b2a2cb
Security Audit — socket — shopify-admin