macOS
brew install sh4d0wuplocal Homebrew formula metadata
安装
brew install sh4d0wuplocal Homebrew formula metadata
nix profile install nixpkgs#sh4d0wupnixpkgs package indexes · pkgs/by-name/sh/sh4d0wup/package.nix · 来源: api.github.com
sudo pacman -S sh4d0wupArch Linux sync databases · sh4d0wup · 来源: geo.mirror.pkgbuild.com
概览
Signing-key abuse and update exploitation framework
历史
sh4d0wup is kpcyrd's Rust-based signing-key abuse and update-exploitation framework. It can proxy a legitimate update service, selectively alter artifacts, and sign or route malicious updates for controlled supply-chain security research.
kpcyrd developed sh4d0wup as a Rust framework for researching 'shadow updates': targeted, malicious updates that remain acceptable to clients because they carry valid signatures. The official repository documents continued development across multiple releases and support for several package and artifact formats.
The input records packages for Homebrew, Nix, and pacman, while the official README notes an Arch Linux binary and an official container image. This reflects adoption mainly among security researchers and distribution or update-system testers rather than general application users.
Security practitioners define attacks in YAML 'plot' files describing routing, selectors, artifact transformations, signatures, and keys. They can build plots in advance, launch a bait update server, proxy legitimate traffic, mutate packages or images, generate or use signing keys, and test whether an attack still executes. Plot files are user-supplied attack definitions, not a documented fixed-location application configuration file.
sh4d0wup is notable to package specialists because it turns package metadata, artifact formats, signing infrastructure, dependency resolution, and targeted update routing into an explicit security-testing surface. It demonstrates how valid signatures alone do not guarantee that every client received the same update.
安全态势
escape, surveillance, or offensive capability signal.
red 风险 · 中 置信度 · escape-surveillance-offensive
在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。
可执行文件
| 命令 | 类型 | 暴露范围 | 备注 |
|---|---|---|---|
sh4d0wup | cli | 全局可执行文件 |
新鲜度
这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。
https://github.com/kpcyrd/sh4d0wup
安装元数据
| 软件包键 | brew:sh4d0wup |
|---|---|
| 版本 | 0.11.1 |
| 软件包管理器 | Homebrew |
| 软件包管理器页面 | https://formulae.brew.sh/formula/sh4d0wup |
| 主页 | https://github.com/kpcyrd/sh4d0wup |
| 仓库 | https://github.com/kpcyrd/sh4d0wup |
| 许可证 | GPL-3.0-or-later |
| 源码归档 | https://github.com/kpcyrd/sh4d0wup/archive/refs/tags/v0.11.1.tar.gz |
| 最后更新 | 2026-09-14T12:20:55+02:00 |
| Pulse | updated |
| 依赖 | openssl@3, pcsc-lite, xz, zstd |
| 构建依赖 | llvm, pkgconf, rust |
| Bottle | 可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定义 |
| 服务 | 未声明 |
注册表事实
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | sh4d0wup |
| Version Scheme | 0 |
| Revision | 0 |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
源数据库匹配
匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。
sh4d0wup
nix profile install nixpkgs#sh4d0wupsh4d0wup 0.11.1-1
Signing-key abuse and update exploitation framework
https://github.com/kpcyrd/sh4d0wup
sudo pacman -S sh4d0wup来源线索
此页面由 av-web 从 scripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。
View the package source record on GitHub.