
GitHub-gato
GitHub Self-Hosted Runner Enumeration and Attack Tool

GitHub Self-Hosted Runner Enumeration and Attack Tool

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

Proof-of-concept lab demonstrating command injection in GitHub Actions workflow dispatch (CVE-2026-39866). Runs vulnerable and patched versions…

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Github as C2 Demonstration , free API = free C2 Infrastructure

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more…

Cyberdelia, a Collection of Command and Control frameworks

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

OS Command Injection in Health Check → Remote Code Execution

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

PoC exploit for CVE-2018-11235 allowing RCE on git clone --recurse-submodules

Access control for AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run,…

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

A stealthy Python based Windows backdoor that uses Github as a command and control server

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…