# 使用 Homebrew, apt, dnf, MacPorts, Nix, pacman 安装 medusa

查看 medusa 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:medusa
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install medusa
```

  证据: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install medusa
```

  证据: MacPorts ports tree: security/medusa/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- Debian apt (92%):

```sh
sudo apt install medusa
```

  证据: Debian stable package indexes: medusa from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- dnf (92%):

```sh
sudo dnf install medusa
```

  证据: Fedora Rawhide package metadata: medusa from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst

- Nix (92%):

```sh
nix profile install nixpkgs#medusa
```

  证据: nixpkgs package indexes: pkgs/by-name/me/medusa/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S medusa
```

  证据: Arch Linux sync databases: medusa from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

## 软件包事实

- **软件包键:** brew:medusa
- **软件包管理器:** Homebrew
- **软件包管理器页面:** <https://formulae.brew.sh/formula/medusa>
- **版本:** 1.5.1
- **来源摘要:** Solidity smart contract fuzzer powered by go-ethereum
- **主页:** <https://secure-contracts.com/program-analysis/medusa/docs/src/>
- **仓库:** <https://github.com/crytic/medusa>
- **上游文档:** <https://secure-contracts.com/program-analysis/medusa/docs/src/>
- **许可证:** AGPL-3.0-only
- **源码归档:** <https://github.com/crytic/medusa/archive/refs/tags/v1.5.1.tar.gz>
- **最后更新:** 2026-07-29T17:04:53+02:00
- **已生成:** 2026-08-04T22:13:35+00:00

## 可执行文件

- medusa (cli)
- medusa (别名)

## 依赖

- crytic-compile

## 构建依赖

- go

## 安装行为

- post-install 钩子: 未定义
- Bottle: 可用 于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## 版本和新鲜度

- 页面生成时间: 2026-08-04
- 管理器版本: 1.5.1
- 管理器更新时间: 2026-07-29
- 本地数据: OK
- 上游仓库: https://github.com/crytic/medusa
- 检测到的最新版本: v1.5.1 (当前)
## 项目历史与用法

medusa is a cross-platform, go-ethereum-based smart-contract fuzzer from the Crytic ecosystem. Its official README describes it as inspired by Echidna and designed for parallelized fuzz testing through a CLI or Go API.

### 项目历史

The official repository was created in 2023 and its first GitHub release was v0.1.0 in March 2023. The project entered a security tooling space already shaped by Crytic tools such as Echidna and Slither, but focused on a Go implementation powered by go-ethereum.

The documentation grew into a mdBook under Trail of Bits' Building Secure Contracts material, with sections for installation, first steps, project configuration, CLI commands, fuzzing lifecycle, invariant testing, cheatcodes, and an evolving Go API.

### 采用历史

medusa is a specialized package for smart-contract auditors, protocol teams, and Solidity developers who need fuzzing in local or CI workflows. Official installation docs include Go install, Homebrew, Nix, Docker, source builds, and precompiled binaries, which is a strong signal that the project expects package-manager and automation use.

The package input lists Homebrew, Debian, Fedora, MacPorts, Nix, Pacman, and Ubuntu package names, showing that the tool has moved beyond a source-only security project into normal developer-tool distribution channels.

### 使用方式

Users initialize a Solidity project with `medusa init`, which creates `medusa.json`, then run campaigns with commands such as `medusa fuzz --target-contracts ... --test-limit ...`. Official docs recommend placing target contracts and fuzz limits in the project configuration file.

### 为什么软件包爱好者会关心

medusa is interesting to package maintainers because it brings smart-contract fuzzing into a single Go CLI while still interoperating with common Ethereum tooling such as crytic-compile, Slither, Foundry, Hardhat, and go-ethereum. It sits in the same toolbox category as Echidna and Slither, but with a distinct implementation and parallel fuzzing model.

### 时间线

- 2023: Repository is created and v0.1.0 is released.
- 2023: Documentation describes `medusa init`, `medusa fuzz`, and `medusa.json` project configuration workflows.
- 2026: GitHub repository lists v1.5.1 as the latest release.

### Related projects

- medusa is related to Echidna, go-ethereum, crytic-compile, Slither, Foundry, Hardhat, and Trail of Bits' Building Secure Contracts documentation.

### 来源

- <https://api.github.com/repos/crytic/medusa>
- <https://api.github.com/repos/crytic/medusa/releases>
- <https://github.com/crytic/medusa>
- <https://raw.githubusercontent.com/crytic/medusa/master/docs/src/cli/init.md>
- <https://raw.githubusercontent.com/crytic/medusa/master/docs/src/getting_started/first_steps.md>
- <https://raw.githubusercontent.com/crytic/medusa/master/docs/src/getting_started/installation.md>
- <https://secure-contracts.com/program-analysis/medusa/docs/src/>


## 安全说明

narrow executable package without higher-risk signals.

- **Geiger 风险:** 绿色 / 低
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: medusa.json
## 源数据库详情

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** medusa
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Conflicts With:** bash-completion
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## 其他软件包管理器记录

- Debian apt - medusa - 2.3-2: normalized package name match | Debian stable package indexes: medusa from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | fast, parallel, modular, login brute-forcer for network services | http://foofus.net/?page_id=51
- Nix - medusa: normalized package name match | nixpkgs package indexes: pkgs/by-name/me/medusa/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Ubuntu apt - medusa - 2.2-7build3: normalized package name match | Ubuntu 24.04 LTS package indexes: medusa from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | fast, parallel, modular, login brute-forcer for network services | http://foofus.net/?page_id=51
- dnf - medusa - 2.3-8.20240130git4e9be7e.fc45: normalized package name match | Fedora Rawhide package metadata: medusa from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst | Speedy, parallel, and modular, login brute-forcer | http://www.foofus.net/jmk/medusa/medusa.html
- pacman - medusa - 2.2-13: normalized package name match | Arch Linux sync databases: medusa from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | Speedy, massively parallel and modular login brute-forcer for network | http://www.foofus.net/jmk/medusa/medusa.html
- MacPorts - medusa: normalized package name match | MacPorts ports tree: security/medusa/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1


## 相关链接

- [Terminal utility packages](https://pkg.so/zh-hans/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Language runtime packages](https://pkg.so/zh-hans/language-runtime-packages/) - Matched language runtime, compiler, or interpreter metadata.
- [Networking and protocol packages](https://pkg.so/zh-hans/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [Security and crypto packages](https://pkg.so/zh-hans/security-crypto-tools/) - Matched security, identity, cryptography, password, signing, or certificate metadata.
- [crytic-compile](https://pkg.so/zh-hans/brew/crytic-compile/) - Runtime dependency declared by Homebrew.
- [go](https://pkg.so/zh-hans/brew/go/) - Build dependency declared by Homebrew.
- [radamsa](https://pkg.so/zh-hans/brew/radamsa/) - Shares pkgdb curated category or tags: cli, fuzzer, fuzzing, security, security-testing.
- [ffuf](https://pkg.so/zh-hans/brew/ffuf/) - Shares pkgdb curated category or tags: cli, fuzzing, security.
- [echidna](https://pkg.so/zh-hans/brew/echidna/) - Shares pkgdb curated category or tags: cli, fuzzing, security, security-testing, smart-contracts.
- [slither-analyzer](https://pkg.so/zh-hans/brew/slither-analyzer/) - Shares pkgdb curated category or tags: cli, security, smart-contracts, solidity.
- [afl++](https://pkg.so/zh-hans/brew/afl/) - Shares pkgdb curated category or tags: cli, fuzzing, security, security-testing.
- [dnsgen](https://pkg.so/zh-hans/brew/dnsgen/) - Shares pkgdb curated category or tags: cli, security, security-testing.
- [proxelar](https://pkg.so/zh-hans/brew/proxelar/) - Shares pkgdb curated category or tags: cli, security, security-testing.

## Combined YAML source

View the package source record on GitHub. [combined/medusa.yml](https://github.com/mxcl/pkgdb/blob/main/combined/medusa.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated configuration and credential file locations
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
