pkg.soopen package index

brew / 順位 9443

sh4d0wup を Homebrew, Nix, pacman でインストール

sh4d0wup のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install sh4d0wup

local Homebrew formula metadata

Linux

Nix確認済み · 92%
nix profile install nixpkgs#sh4d0wup

nixpkgs package indexes · pkgs/by-name/sh/sh4d0wup/package.nix · ソース: api.github.com

Arch Linux pacman確認済み · 92%
sudo pacman -S sh4d0wup

Arch Linux sync databases · sh4d0wup · ソース: geo.mirror.pkgbuild.com

概要

パッケージ概要

Signing-key abuse and update exploitation framework

コマンドとエイリアス

  • sh4d0wup

履歴

プロジェクトの歴史と使われ方

sh4d0wup is kpcyrd's Rust-based signing-key abuse and update-exploitation framework. It can proxy a legitimate update service, selectively alter artifacts, and sign or route malicious updates for controlled supply-chain security research.

プロジェクトの歴史

kpcyrd developed sh4d0wup as a Rust framework for researching 'shadow updates': targeted, malicious updates that remain acceptable to clients because they carry valid signatures. The official repository documents continued development across multiple releases and support for several package and artifact formats.

採用の歴史

The input records packages for Homebrew, Nix, and pacman, while the official README notes an Arch Linux binary and an official container image. This reflects adoption mainly among security researchers and distribution or update-system testers rather than general application users.

使われ方

Security practitioners define attacks in YAML 'plot' files describing routing, selectors, artifact transformations, signatures, and keys. They can build plots in advance, launch a bait update server, proxy legitimate traffic, mutate packages or images, generate or use signing keys, and test whether an attack still executes. Plot files are user-supplied attack definitions, not a documented fixed-location application configuration file.

パッケージ好きにとっての重要性

sh4d0wup is notable to package specialists because it turns package metadata, artifact formats, signing infrastructure, dependency resolution, and targeted update routing into an explicit security-testing surface. It demonstrates how valid signatures alone do not guarantee that every client received the same update.

タイムライン

  • 2022: Examples in the official README demonstrate infection of pacman, Debian, ELF, and OCI artifacts.
  • 2025: Official repository lists version 0.11.0 released on April 2.

Related projects

  • The framework operates on ecosystems and formats including pacman packages, Debian packages, OCI images, Rust distribution updates, ELF binaries, and Git commits. The maintainer's related supply-chain work includes rebuilderd and reproducible-build experiments.

ソース

  • Official repository and README: https://github.com/kpcyrd/sh4d0wup
  • Official repository release list: https://github.com/kpcyrd/sh4d0wup/releases
  • input.source_facts.package-manager

セキュリティ状態

リスクレベル: red

escape, surveillance, or offensive capability signal.

リスク分類器

リスク red · 信頼度 中 · escape-surveillance-offensive

理由

  • escape, surveillance, or offensive capability signal

信号

  • text:exploit

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • 4 件の実行時依存関係とともにインストールされます。
  • ビルドメタデータには 3 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
sh4d0wupcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-09-19
マネージャ版0.11.1
マネージャ更新日2026-09-14
ローカルデータOK
上流最新
検出された最新v0.11.1

https://github.com/kpcyrd/sh4d0wup

  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:sh4d0wup
バージョン0.11.1
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/sh4d0wup
ホームページhttps://github.com/kpcyrd/sh4d0wup
リポジトリhttps://github.com/kpcyrd/sh4d0wup
ライセンスGPL-3.0-or-later
ソースアーカイブhttps://github.com/kpcyrd/sh4d0wup/archive/refs/tags/v0.11.1.tar.gz
最終更新2026-09-14T12:20:55+02:00
Pulseupdated
依存関係openssl@3, pcsc-lite, xz, zstd
ビルド依存関係llvm, pkgconf, rust
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namesh4d0wup
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

sh4d0wup

nix profile install nixpkgs#sh4d0wup
  • normalized package name match
  • 一致条件: Sh4d0wup
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/sh/sh4d0wup/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

sh4d0wup 0.11.1-1

Signing-key abuse and update exploitation framework

https://github.com/kpcyrd/sh4d0wup

sudo pacman -S sh4d0wup
  • License: GPL-3.0-or-later
  • Architecture: x86_64
  • 14 依存関係
  • normalized package name match
  • 一致条件: Sh4d0wup
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: sh4d0wup from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation