pkg.soopen package index

brew / rank 9443

Install sh4d0wup with Homebrew, Nix, pacman

Signing-key abuse and update exploitation framework. Version 0.11.1 via Homebrew; verified 2026-09-14. Also installable with nix: nix profile install nixpkgs#sh4d0wup.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install sh4d0wup

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#sh4d0wup

nixpkgs package indexes · pkgs/by-name/sh/sh4d0wup/package.nix · source: api.github.com

Arch Linux pacmanverified · 92%
sudo pacman -S sh4d0wup

Arch Linux sync databases · sh4d0wup · source: geo.mirror.pkgbuild.com

overview

Package summary

Signing-key abuse and update exploitation framework

Commands and aliases

  • sh4d0wup

history

Project history and usage

sh4d0wup is kpcyrd's Rust-based signing-key abuse and update-exploitation framework. It can proxy a legitimate update service, selectively alter artifacts, and sign or route malicious updates for controlled supply-chain security research.

Project history

kpcyrd developed sh4d0wup as a Rust framework for researching 'shadow updates': targeted, malicious updates that remain acceptable to clients because they carry valid signatures. The official repository documents continued development across multiple releases and support for several package and artifact formats.

Adoption history

The input records packages for Homebrew, Nix, and pacman, while the official README notes an Arch Linux binary and an official container image. This reflects adoption mainly among security researchers and distribution or update-system testers rather than general application users.

How it is used

Security practitioners define attacks in YAML 'plot' files describing routing, selectors, artifact transformations, signatures, and keys. They can build plots in advance, launch a bait update server, proxy legitimate traffic, mutate packages or images, generate or use signing keys, and test whether an attack still executes. Plot files are user-supplied attack definitions, not a documented fixed-location application configuration file.

Why package nerds care

sh4d0wup is notable to package specialists because it turns package metadata, artifact formats, signing infrastructure, dependency resolution, and targeted update routing into an explicit security-testing surface. It demonstrates how valid signatures alone do not guarantee that every client received the same update.

Timeline

  • 2022: Examples in the official README demonstrate infection of pacman, Debian, ELF, and OCI artifacts.
  • 2025: Official repository lists version 0.11.0 released on April 2.

Related projects

  • The framework operates on ecosystems and formats including pacman packages, Debian packages, OCI images, Rust distribution updates, ELF binaries, and Git commits. The maintainer's related supply-chain work includes rebuilderd and reproducible-build experiments.

Sources

  • Official repository and README: https://github.com/kpcyrd/sh4d0wup
  • Official repository release list: https://github.com/kpcyrd/sh4d0wup/releases
  • input.source_facts.package-manager

security posture

Risk level: red

escape, surveillance, or offensive capability signal.

Risk classifier

red risk · medium confidence · escape-surveillance-offensive

Why

  • escape, surveillance, or offensive capability signal

Signals

  • text:exploit

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Installs with 4 runtime dependencies.
  • Build metadata lists 3 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
sh4d0wupcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version0.11.1
manager updated2026-09-14
local dataok
upstreamcurrent
latest detectedv0.11.1

https://github.com/kpcyrd/sh4d0wup

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:sh4d0wup
Version0.11.1
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/sh4d0wup
Homepagehttps://github.com/kpcyrd/sh4d0wup
Repositoryhttps://github.com/kpcyrd/sh4d0wup
LicenseGPL-3.0-or-later
Source archivehttps://github.com/kpcyrd/sh4d0wup/archive/refs/tags/v0.11.1.tar.gz
Last updated2026-09-14T12:20:55+02:00
Pulseupdated
Dependenciesopenssl@3, pcsc-lite, xz, zstd
Build dependenciesllvm, pkgconf, rust
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namesh4d0wup
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

sh4d0wup

nix profile install nixpkgs#sh4d0wup
  • normalized package name match
  • Matched by: Sh4d0wup
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/sh/sh4d0wup/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

sh4d0wup 0.11.1-1

Signing-key abuse and update exploitation framework

https://github.com/kpcyrd/sh4d0wup

sudo pacman -S sh4d0wup
  • License: GPL-3.0-or-later
  • Architecture: x86_64
  • 14 dependencies
  • normalized package name match
  • Matched by: Sh4d0wup
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: sh4d0wup from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation