Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
camjacking — CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the negligence of people, and is used to identify weaknesses in an organization's security infrastructure. | Kitploit
Tools/GitHubGitHub/cappricio-securities/camjacking
Phishing ToolsImpersonation ToolsInformation GatheringWeb SecurityPenetration TestingSocial EngineeringLearning & EducationRed Teaming

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
cappricio-securities/camjacking

camjacking

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the negligence of people, and is used to identify weaknesses in an organization's security infrastructure.

View Repository
6318327 months agoReviewed by Kitploit

Camjacking

CamJacking is an enterprise-grade security awareness training framework designed to simulate realistic phishing attacks targeting camera permissions and user awareness

Logo GitHub Stars MIT License npm version Node Version


🎯 What is CamJacking?

CamJacking is an enterprise-grade security awareness training framework designed to simulate realistic phishing attacks targeting camera permissions and user awareness. Built for ethical hackers, penetration testers, and security professionals, CamJacking enables organizations to:

✅ Assess employee awareness and susceptibility to social engineering
✅ Train teams on camera security risks and best practices
✅ Simulate realistic attack scenarios in controlled lab environments
✅ Measure security posture with detailed analytics and reporting
✅ Educate through hands-on, practical cybersecurity training

🚨 DISCLAIMER: This tool is strictly for authorized security training, educational purposes, and lab environments only. Unauthorized use is illegal and unethical. Always obtain proper authorization before testing.


📌 Features

  • 📸 Camera Phishing Create realistic camera capture pages for security awareness and testing.
  • 🖥️ Admin Dashboard (GUI Panel) Manage campaigns, view logs, and monitor activity through a web-based interface.
  • 🤖 Telegram Bot Integration Receive real-time alerts and captured data directly on Telegram.
  • 🔄 Template Auto-Updating Automatically fetch and update phishing templates with the latest designs.
  • 🗂️ Campaign History & Logs View and manage previous campaigns with detailed activity records.
  • 🌐 Automatic Port Forwarding (Local → Internet) Expose local services to the internet automatically for testing and demos.

⚠️ Requirements

  • GIT CLI
  • Node JS
  • npm
  • cloudflared (CLI)

✅ Supported Platforms

PlatformSupportedNotes
Debian / Kali / Ubuntu✅Recommended for best compatibility
macOS✅Works well with Homebrew setup
Windows⚠️ PartialUse WSL for best experience

📦 Libraries Used

The project relies on the following Node.js packages:

  • axios – HTTP client for API requests
  • bcrypt – Secure password hashing
  • body-parser – Parse incoming request bodies
  • cors – Cross-origin request handling
  • crypto – Cryptographic utilities
  • dotenv – Environment variable management
  • express – Web server framework
  • form-data – Multipart form handling
  • jsonwebtoken – JWT-based authentication
  • lowdb – Lightweight JSON database
  • md5 – Legacy hashing (for compatibility)
  • multer – File upload handling
  • uuid – Unique ID generation

💡 Tip: Make sure you’re running a recent Node.js LTS version (v18 or later) for best stability and security.


⚡Installation and Config

# Install globally
npm install camjacking -g
# Start the Camjacking tool
camjacking
  • Open the Admin page: https://cappriciosec.com/camjacking 👉 Click here to open and log in.
ParameterTypeDefault Credentials
usernamestringcappriciosec
passwordstringcappriciosec@hacker

🚨 Note: Before opening the webpage, make sure the Camjacking tool is running locally. This URL internally checks http://localhost:5000 to verify whether the service is running.

  • If the local service is running, the login page will be displayed.
  • If it is not running, you will be redirected to the landing page.

After logging in with the default credentials, you can update your username and password from the Admin Dashboard.


🤖 Configure Telegram Bot

  • Open Telegram and search for 👉 @CappricioSecuritiesTools_bot

  • Click Start or send /start, then tap the Get Chat ID button.

  • Copy the Chat ID shown by the bot.

  • Go back to the Admin Dashboard → Profile / Settings → Paste the Chat ID and save your profile.

💡 Tip: Once configured, you’ll receive real-time notifications and alerts from Camjacking directly in Telegram.


📝 Adding Custom Templates

When the Camjacking tool starts, it automatically clones the template repository from:
https://github.com/Cappricio-Securities/camjacking-templates
into the local directory: ~/camjacking-templates/

If you already have custom templates in this folder, they will not be deleted.
Your existing templates will be preserved, and newly updated templates from the repository will be added automatically.


📂 Template Structure

You can add your own custom templates by creating a new folder inside:

~/camjacking-templates/

Example structure:

camjacking-templates/
├── your-template-name/
│   ├── index.html
│   └── index.css

You can find the complete setup instructions in this repository: https://github.com/Cappricio-Securities/camjacking-templates 👉 Clickme

⚠️ Naming Rules

  • Template folder names must not contain spaces or special characters.
  • Only the following characters are supported:
    A–Z, a–z, 0–9, _ (underscore), - (hyphen)
  • Do not use the same name for multiple templates.

⚙️ How Templates Work

  • The server automatically loads the correct template based on user input or the default configuration.
  • You do not need to write any extra code to access the camera or collect data.
  • Camjacking dynamically injects the required camera access logic into your templates and automatically handles routing to receive captured images.

💡 Tip: Focus only on the HTML/CSS design of your template. The tool handles camera access and data collection for you.

⚡ Quick Start

To start a new campaign, simply run:

camjacking

You will be greeted with the main menu:

┌──(Hacker@linux)-[~]
└─$ camjacking
                                                                         v2.0

 ██████╗ █████╗ ███╗   ███╗     ██╗ █████╗  ██████╗██╗  ██╗██╗███╗   ██╗ ██████╗
██╔════╝██╔══██╗████╗ ████║     ██║██╔══██╗██╔════╝██║ ██╔╝██║████╗  ██║██╔════╝
██║     ███████║██╔████╔██║     ██║███████║██║     █████╔╝ ██║██╔██╗ ██║██║  ███╗
██║     ██╔══██║██║╚██╔╝██║██   ██║██╔══██║██║     ██╔═██╗ ██║██║╚██╗██║██║   ██║
╚██████╗██║  ██║██║ ╚═╝ ██║╚█████╔╝██║  ██║╚██████╗██║  ██╗██║██║ ╚████║╚██████╔╝
 ╚═════╝╚═╝  ╚═╝╚═╝     ╚═╝ ╚════╝ ╚═╝  ╚═╝ ╚═════╝╚═╝  ╚═╝╚═╝╚═╝  ╚═══╝ ╚═════╝
                                                         Author: @karthithehacker
                                                         Website: karthithehacker.com

            Main Menu
┏━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ No. ┃ Option                   ┃
Download Tool