macOS
brew install sh4d0wuplocal Homebrew formula metadata
brew / rang 9443
Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de sh4d0wup pour les workflows d'agents IA.
installation
brew install sh4d0wuplocal Homebrew formula metadata
nix profile install nixpkgs#sh4d0wupnixpkgs package indexes · pkgs/by-name/sh/sh4d0wup/package.nix · Source: api.github.com
sudo pacman -S sh4d0wupArch Linux sync databases · sh4d0wup · Source: geo.mirror.pkgbuild.com
aperçu
Signing-key abuse and update exploitation framework
historique
sh4d0wup is kpcyrd's Rust-based signing-key abuse and update-exploitation framework. It can proxy a legitimate update service, selectively alter artifacts, and sign or route malicious updates for controlled supply-chain security research.
kpcyrd developed sh4d0wup as a Rust framework for researching 'shadow updates': targeted, malicious updates that remain acceptable to clients because they carry valid signatures. The official repository documents continued development across multiple releases and support for several package and artifact formats.
The input records packages for Homebrew, Nix, and pacman, while the official README notes an Arch Linux binary and an official container image. This reflects adoption mainly among security researchers and distribution or update-system testers rather than general application users.
Security practitioners define attacks in YAML 'plot' files describing routing, selectors, artifact transformations, signatures, and keys. They can build plots in advance, launch a bait update server, proxy legitimate traffic, mutate packages or images, generate or use signing keys, and test whether an attack still executes. Plot files are user-supplied attack definitions, not a documented fixed-location application configuration file.
sh4d0wup is notable to package specialists because it turns package metadata, artifact formats, signing infrastructure, dependency resolution, and targeted update routing into an explicit security-testing surface. It demonstrates how valid signatures alone do not guarantee that every client received the same update.
posture de sécurité
escape, surveillance, or offensive capability signal.
risque red · confiance moyen · escape-surveillance-offensive
Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.
exécutables
| Commande | Type | Exposition | Note |
|---|---|---|---|
sh4d0wup | cli | exécutable global |
fraîcheur
Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.
https://github.com/kpcyrd/sh4d0wup
métadonnées d'installation
| Clé du paquet | brew:sh4d0wup |
|---|---|
| Version | 0.11.1 |
| Gestionnaire de paquets | Homebrew |
| Page du gestionnaire de paquets | https://formulae.brew.sh/formula/sh4d0wup |
| Page d'accueil | https://github.com/kpcyrd/sh4d0wup |
| Dépôt | https://github.com/kpcyrd/sh4d0wup |
| Licence | GPL-3.0-or-later |
| Archive source | https://github.com/kpcyrd/sh4d0wup/archive/refs/tags/v0.11.1.tar.gz |
| Dernière mise à jour | 2026-09-14T12:20:55+02:00 |
| Pulse | updated |
| Dépendances | openssl@3, pcsc-lite, xz, zstd |
| Dépendances de compilation | llvm, pkgconf, rust |
| Bouteille | disponible (sur arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| post-install Homebrew | non défini |
| Service | aucun déclaré |
faits du registre
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | sh4d0wup |
| Version Scheme | 0 |
| Revision | 0 |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
correspondances dans les bases sources
Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.
sh4d0wup
nix profile install nixpkgs#sh4d0wupsh4d0wup 0.11.1-1
Signing-key abuse and update exploitation framework
https://github.com/kpcyrd/sh4d0wup
sudo pacman -S sh4d0wuppiste source
Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.