# Install bkcrack with Homebrew, Nix, zypper

Crack legacy zip encryption with Biham and Kocher's known plaintext attack. Version 1.8.1 via Homebrew; verified from local package data. Also installable with nix: nix profile install nixpkgs#bkcrack.

## Install

```sh
sudo av install brew:bkcrack
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install bkcrack
```

  Evidence: local Homebrew formula metadata

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#bkcrack
```

  Evidence: nixpkgs package indexes: pkgs/by-name/bk/bkcrack/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- zypper (92%):

```sh
sudo zypper install bkcrack
```

  Evidence: openSUSE Tumbleweed package metadata: bkcrack from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

## Package facts

- **Package key:** brew:bkcrack
- **Package manager:** Homebrew
- **Package manager page:** <https://formulae.brew.sh/formula/bkcrack>
- **Version:** 1.8.1
- **Source summary:** Crack legacy zip encryption with Biham and Kocher's known plaintext attack
- **Homepage:** <https://github.com/kimci86/bkcrack>
- **Repository:** <https://github.com/kimci86/bkcrack>
- **License:** Zlib
- **Source archive:** <https://github.com/kimci86/bkcrack/archive/refs/tags/v1.8.1.tar.gz>
- **Generated:** 2026-08-04T22:13:35+00:00

## Executables

- bkcrack (cli)
- bkcrack (alias)

## Build dependencies

- cmake

## Install behavior

- Post-install hook: not defined
- Bottle: available on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## Freshness

- Page generated: 2026-08-04
- Package-manager version: 1.8.1
- Local data: ok
- Upstream repository: https://github.com/kimci86/bkcrack
- Upstream latest detected: v1.8.1 (current)
- info: No package-manager update timestamp was available.
## Project history and usage

bkcrack is a command-line cryptanalysis tool for legacy ZIP encryption, specifically the traditional PKWARE/ZipCrypto scheme. Its package-manager identity is narrow and practical: a small utility installed when a user needs a known-plaintext attack workflow against old encrypted ZIP archives.

### Project history

The project was published on GitHub in 2016 and describes itself as an implementation of Eli Biham and Paul C. Kocher's known-plaintext attack on the PKZIP stream cipher. Its documentation explains the ZipCrypto keystream model and frames bkcrack as a way to recover internal keys, remove or change archive passwords, and attempt password recovery.

### Adoption history

bkcrack grew from a specialist security tool into a packaged CLI available through Homebrew, Nix, openSUSE/zypper, and upstream GitHub release artifacts for Ubuntu, macOS, and Windows. That distribution pattern reflects a tool useful enough for repeatable incident-response and recovery workflows but still niche compared with general password crackers.

### How it is used

Typical use starts with a ciphertext entry and 12 or more bytes of known plaintext, often supplied from another ZIP entry or file. Users run bkcrack to recover the ZipCrypto internal state, then decrypt data, create an unencrypted copy of the archive, change the password, or search for the original password from recovered keys.

### Why package nerds care

Package nerds care about bkcrack because it packages a classic academic break of legacy ZIP encryption into a reproducible CLI with cross-platform binaries. It is a reminder that 'ZIP password support' in archive tools historically meant weak ZipCrypto unless AES or another modern scheme was explicitly used.

### Timeline

- 1994: Biham and Kocher publish the known-plaintext attack on the PKZIP stream cipher.
- 2016: bkcrack repository is created on GitHub.
- 2020: v1.0.0 appears as the first GitHub release in the current release history.
- 2020s: bkcrack becomes available through Homebrew and other Unix package sets.

### Related projects

- Related tools include zip password recovery and auditing utilities, but bkcrack is specifically centered on ZipCrypto known-plaintext recovery rather than generic brute-force cracking.
- The underlying cryptanalytic reference is Biham and Kocher's PKZIP stream-cipher paper, which bkcrack cites directly from its README.

### Sources

- <https://doi.org/10.1007/3-540-60590-8_12>
- <https://github.com/kimci86/bkcrack#readme>
- <https://github.com/kimci86/bkcrack/releases>
- source_facts.package-manager


## Security Notes

broad file, network, media, or database tool signal.

- **Geiger risk:** blue / medium
- broad file, network, media, or database tool signal

## Source Database Details

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** bkcrack
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## Other Package-Manager Records

- Nix - bkcrack: normalized package name match | nixpkgs package indexes: pkgs/by-name/bk/bkcrack/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- zypper - bkcrack - 1.8.1-1.5: normalized package name match | openSUSE Tumbleweed package metadata: bkcrack from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Crack legacy zip encryption with Biham and Kocher's known plaintext attack | https://github.com/kimci86/bkcrack/


## Related links

- [Source-control packages](https://pkg.so/source-control-tools/) - Belongs to a source-control command family.
- [Secret-risk packages](https://pkg.so/secret-risk-packages/) - Has protected-tool coverage, approval-gate, or non-low Geiger security signals.
- [Terminal utility packages](https://pkg.so/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Archive and compression packages](https://pkg.so/archive-compression-tools/) - Matched archive or compression metadata.
- [cmake](https://pkg.so/brew/cmake/) - Build dependency declared by Homebrew.
- [fcrackzip](https://pkg.so/brew/fcrackzip/) - Shares pkgdb curated category or tags: cli, password-recovery, security, zip.
- [hashcat](https://pkg.so/brew/hashcat/) - Shares pkgdb curated category or tags: cli, password-recovery, security.
- [pdfcrack](https://pkg.so/brew/pdfcrack/) - Shares pkgdb curated category or tags: cli, password-recovery, security.
- [pdfrip](https://pkg.so/brew/pdfrip/) - Shares pkgdb curated category or tags: cli, password-recovery, security.
- [cifer](https://pkg.so/brew/cifer/) - Shares pkgdb curated category or tags: cli, cryptanalysis, security.
- [truecrack](https://pkg.so/brew/truecrack/) - Shares pkgdb curated category or tags: cli, password-recovery, security.
- [wirouter_keyrec](https://pkg.so/brew/wirouter-keyrec/) - Shares pkgdb curated category or tags: cli, password-recovery, security.
- [openssl@3](https://pkg.so/brew/openssl-3/) - Shares pkgdb curated category or tags: cli, security.
- [authoscope](https://pkg.so/brew/authoscope/) - Security-sensitive metadata or terminology overlaps. Shared terms: attack, cli, password, security.

## Combined YAML source

View the package source record on GitHub. [combined/bkcrack.yml](https://github.com/mxcl/pkgdb/blob/main/combined/bkcrack.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
