shopify-storefront-graphql

Fail

Audited by Socket on Sep 14, 2026

2 alerts found:

Obfuscated FileAnomaly
Obfuscated FileHIGH
assets/storefront-graphql_unstable.json.br

The fragment is an opaque binary-like payload with no directly observable malicious behavior. Its format and role are indeterminate, and hidden decoder or loader logic in the larger file would require separate analysis. Treat the file as requiring further review rather than as confirmed malware.

Confidence: 90%
AnomalyLOW
scripts/track-telemetry.ps1

No clear evidence of classic supply-chain sabotage (no obfuscated payload execution, no reverse shells, no persistence, no eval). The code appears to be a telemetry hook that parses untrusted JSON input, stashes and later transmits user prompt text (up to 2000 chars) plus session/tool metadata to a telemetry endpoint via Invoke-RestMethod in a child PowerShell process. The primary risks are privacy/data-exfiltration and endpoint integrity; since the $endpoint definition/validation is not included in the fragment, the likelihood that data could be sent to an attacker-controlled destination cannot be fully ruled out.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Sep 14, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/shopify%2Fshopify-ai-toolkit%2Fshopify-storefront-graphql%2F@44c2c65bf9e49854a57063da8d3a7c2c33f4a09cd13cfde220127ccffe577784
Security Audit — socket — shopify-storefront-graphql