PkgRadar

Go modules · proxy.golang.org

github.com/TyrusRC/assay

Reverse Shell: matched "bash -i >&" — reverse-shell shape

Why PkgRadar flagged v0.0.0-20260605114847-a79e3505e61b

SeveritySignalEvidence
highReverse Shellmatched "bash -i >&" — reverse-shell shape · github.com/tyrusrc/[email protected]/internal/payloads/cmdi/cmdi.go
highReverse Shellmatched "bash -i >&" — reverse-shell shape · github.com/tyrusrc/[email protected]/internal/payloads/cmdi/shellshock.go
highDNS / OAST exfiltrationmatched "dig $(" · github.com/tyrusrc/[email protected]/internal/payloads/cmdi/cmdi.go
highDNS / OAST exfiltrationmatched "burpcollaborator.net" · github.com/tyrusrc/[email protected]/internal/payloads/ssrf/ssrf.go
mediumRemote Payloadmatched "cURL " · github.com/tyrusrc/[email protected]/cmd/assay/cmd/scan_flags.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/tyrusrc/[email protected]/internal/detection/racecond/sync_h1.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/tyrusrc/[email protected]/internal/detection/racecond/sync_h2.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/tyrusrc/[email protected]/internal/detection/tls/analyzer.go
mediumRemote Payloadmatched "curl " · github.com/tyrusrc/[email protected]/internal/payloads/arginject/detector.go
mediumRemote Payloadmatched "curl " · github.com/tyrusrc/[email protected]/internal/payloads/cmdi/cmdi.go
mediumRemote Payloadmatched "curl " · github.com/tyrusrc/[email protected]/internal/payloads/javareflect/javareflect.go
mediumRemote Payloadmatched "curl " · github.com/tyrusrc/[email protected]/internal/payloads/nodejsinject/nodejsinject.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260605114847-a79e3505e61bHigh risk2072026-06-20

Block this in CI

PkgRadar gates github.com/TyrusRC/assay (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/TyrusRC/[email protected]