一键导入
malware-game-cheat-detection
Detect and analyze malicious game cheating software and trainer malware distributed as open source projects
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Detect and analyze malicious game cheating software and trainer malware distributed as open source projects
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
Orchestrate psychology clinic workflows with AI-powered scheduling, WhatsApp automation, AFIP billing, and video consultations for Argentine practitioners
SaaS platform for psychology clinics with intelligent scheduling, WhatsApp automation, AFIP billing, videollamadas, and Claude AI integration
Build and customize the Sesión mental health practice management platform with appointment scheduling, WhatsApp automation, AFIP billing, and Claude AI integration
Orchestrate psychology clinic operations with AI-powered scheduling, WhatsApp automation, AFIP billing, and secure video consultations for Argentine mental health practitioners
Connect AI agents to a running Tabbit browser instance via Chrome DevTools Protocol (CDP) and control it through agent-browser
AI-powered mental health practice management platform for Argentina with WhatsApp automation, AFIP-compliant invoicing, and video consultations
基于 SOC 职业分类
| name | malware-game-cheat-detection |
| description | Detect and analyze malicious game cheating software and trainer malware distributed as open source projects |
| triggers | ["analyze this game trainer repository","check if this cheat software is malware","scan this trainer for malicious code","is this game hack tool safe","detect malware in gaming utilities","analyze suspicious game modding tool","investigate this ESP wallhack project","review this aimbot trainer repository"] |
Skill by ara.so — Devtools Skills collection.
This skill helps identify malicious game trainer and cheat software disguised as legitimate open source projects. These repositories typically promise game enhancements (ESP, aimbot, god mode) but deliver malware, keyloggers, or ransomware.
⚠️ CRITICAL WARNING: The project XFaltixX/MECCHA-CHAMELEON-Trainer-Client exhibits classic malware distribution patterns.
# Detection heuristics for malware trainer repositories
import re
from dataclasses import dataclass
@dataclass
class MalwareIndicators:
external_download: bool = False
password_protected: bool = False
admin_required: bool = False
executable_only: bool = False
suspicious_domain: bool = False
fake_metrics: bool = False
def risk_score(self) -> int:
"""Calculate risk score (0-100)"""
indicators = [
self.external_download,
self.password_protected,
self.admin_required,
self.executable_only,
self.suspicious_domain,
self.fake_metrics
]
return sum(indicators) * 16 # 6 indicators × 16 ≈ 100
def analyze_readme(readme_content: str) -> MalwareIndicators:
"""Analyze README for malware patterns"""
indicators = MalwareIndicators()
# Check for external downloads
external_patterns = [
r'https?://[^\s]+\.(zip|rar|exe|7z)',
r'download.*archive',
r'mega\.nz|mediafire|anonfiles|discord\.com/attachments'
]
indicators.external_download = any(
re.search(p, readme_content, re.I)
for p in external_patterns
)
# Check for password protection
indicators.password_protected = bool(
re.search(r'password[:\s]+[`"\']?\w+', readme_content, re.I)
)
# Check for admin requirement
indicators.admin_required = bool(
re.search(r'run as administrator', readme_content, re.I)
)
# Check for suspicious domains
suspicious_domains = ['netlify.app', 'github.io', 'vercel.app']
indicators.suspicious_domain = any(
domain in readme_content.lower()
for domain in suspicious_domains
if 'download' in readme_content.lower()
)
return indicators
# Example usage
readme = """
Download: https://skydock.netlify.app/trainer.zip
Password: trainer2026
Run as Administrator
"""
result = analyze_readme(readme)
print(f"Risk Score: {result.risk_score()}/100")
# Output: Risk Score: 64/100
# scan_repository.py
import os
import subprocess
from pathlib import Path
def scan_repository(repo_path: str) -> dict:
"""Scan repository for malware indicators"""
results = {
'has_source_code': False,
'has_executables': False,
'has_suspicious_files': False,
'file_count': 0
}
path = Path(repo_path)
# Check for actual source files
source_extensions = {'.py', '.js', '.go', '.rs', '.cpp', '.c'}
source_files = [
f for f in path.rglob('*')
if f.suffix in source_extensions
]
results['has_source_code'] = len(source_files) > 0
# Check for executables
exe_files = list(path.rglob('*.exe')) + list(path.rglob('*.dll'))
results['has_executables'] = len(exe_files) > 0
# Check for suspicious patterns
suspicious = ['.scr', '.bat', '.vbs', '.ps1']
results['has_suspicious_files'] = any(
path.rglob(f'*{ext}') for ext in suspicious
)
results['file_count'] = len(list(path.rglob('*')))
return results
# Scan example
repo_scan = scan_repository('./suspicious-trainer')
if repo_scan['has_executables'] and not repo_scan['has_source_code']:
print("⚠️ WARNING: Executables without source code detected!")
# url_checker.py
import re
from typing import List
from urllib.parse import urlparse
MALICIOUS_PATTERNS = [
r'discord\.com/attachments',
r'cdn\.discord',
r'anonfiles\.',
r'mega\.nz',
r'mediafire\.',
r'wetransfer\.',
r'file\.io',
]
SUSPICIOUS_TLDs = ['.tk', '.ml', '.ga', '.cf', '.gq', '.zip']
def check_url_safety(url: str) -> dict:
"""Check if URL is likely malicious"""
parsed = urlparse(url)
result = {
'url': url,
'is_suspicious': False,
'reasons': []
}
# Check against known malicious patterns
for pattern in MALICIOUS_PATTERNS:
if re.search(pattern, url, re.I):
result['is_suspicious'] = True
result['reasons'].append(f"Matches pattern: {pattern}")
# Check TLD
domain = parsed.netloc.lower()
if any(domain.endswith(tld) for tld in SUSPICIOUS_TLDs):
result['is_suspicious'] = True
result['reasons'].append("Suspicious TLD")
# Check for file extensions in URL
dangerous_exts = ['.exe', '.scr', '.bat', '.zip', '.rar']
if any(url.lower().endswith(ext) for ext in dangerous_exts):
result['is_suspicious'] = True
result['reasons'].append("Direct executable/archive link")
return result
# Example
url = "https://skydock.netlify.app/trainer-archive.zip"
safety = check_url_safety(url)
print(f"Suspicious: {safety['is_suspicious']}")
print(f"Reasons: {', '.join(safety['reasons'])}")
# analyze_meccha_trainer.py
from datetime import datetime
def analyze_repository_metadata(repo_data: dict) -> dict:
"""Analyze repository metadata for fake/inflated metrics"""
created = datetime.fromisoformat(repo_data['created_at'].replace('Z', '+00:00'))
updated = datetime.fromisoformat(repo_data['updated_at'].replace('Z', '+00:00'))
age_days = (updated - created).days
stars = repo_data['stars']
stars_per_day = stars / age_days if age_days > 0 else 0
analysis = {
'age_days': age_days,
'stars_per_day': stars_per_day,
'likely_fake': False,
'warnings': []
}
# New repo with high star velocity = suspicious
if age_days < 7 and stars_per_day > 50:
analysis['likely_fake'] = True
analysis['warnings'].append(
f"Unnaturally high star velocity: {stars_per_day:.0f} stars/day"
)
# Future dates = obviously fake
now = datetime.now(created.tzinfo)
if created > now:
analysis['likely_fake'] = True
analysis['warnings'].append("Created date is in the future!")
# Zero forks/issues but high stars = fake engagement
if stars > 100 and repo_data['forks'] == 0:
analysis['likely_fake'] = True
analysis['warnings'].append("High stars but zero forks (fake engagement)")
return analysis
# Analyze the MECCHA trainer
repo_metadata = {
"created_at": "2026-06-28T07:17:40Z", # FUTURE DATE!
"updated_at": "2026-06-29T15:29:59Z",
"stars": 185,
"forks": 0,
"open_issues": 0
}
result = analyze_repository_metadata(repo_metadata)
print(f"Likely Fake: {result['likely_fake']}")
for warning in result['warnings']:
print(f"⚠️ {warning}")
# legitimate_checker.py
def is_legitimate_game_mod(repo_path: str) -> bool:
"""Check if game modification tool is legitimate"""
legitimacy_checks = {
'has_readable_source': False,
'uses_known_libraries': False,
'has_documentation': False,
'no_external_downloads': False,
'community_verified': False
}
# Check for actual Python/JS/etc source files
import os
source_files = [
f for f in os.listdir(repo_path)
if f.endswith(('.py', '.js', '.ts', '.go'))
]
legitimacy_checks['has_readable_source'] = len(source_files) > 0
# Check if it uses legitimate libraries
if os.path.exists(f"{repo_path}/requirements.txt"):
with open(f"{repo_path}/requirements.txt") as f:
deps = f.read()
known_safe = ['pygame', 'pynput', 'requests']
legitimacy_checks['uses_known_libraries'] = any(
lib in deps for lib in known_safe
)
# Legitimate mods have real documentation
docs = ['README.md', 'CONTRIBUTING.md', 'docs/']
legitimacy_checks['has_documentation'] = any(
os.path.exists(f"{repo_path}/{doc}") for doc in docs
)
return sum(legitimacy_checks.values()) >= 3
# Report malicious repository
# Visit: https://github.com/contact/report-abuse
# Include:
# 1. Repository URL
# 2. Evidence of malware (external download links)
# 3. Type: "Malware distribution"
# report_malware.py
import os
import json
def generate_abuse_report(repo_url: str, evidence: dict) -> str:
"""Generate formatted abuse report"""
report = f"""
MALWARE DISTRIBUTION REPORT
Repository: {repo_url}
Report Date: {evidence['date']}
EVIDENCE:
- External download link: {evidence.get('download_url', 'N/A')}
- Password-protected archive: {evidence.get('password', 'N/A')}
- Requires admin privileges: {evidence.get('admin_required', False)}
- No source code provided: {evidence.get('no_source', False)}
RISK ASSESSMENT:
{evidence.get('risk_assessment', 'High risk malware distribution')}
ADDITIONAL NOTES:
{evidence.get('notes', 'Repository disguised as game cheat tool')}
"""
return report.strip()
# Example
evidence = {
'date': '2024-01-15',
'download_url': 'https://skydock.netlify.app/trainer-archive.zip',
'password': 'trainer2026',
'admin_required': True,
'no_source': True,
'risk_assessment': 'Confirmed malware distribution pattern',
'notes': 'Future creation date (2026), fake stars, external download only'
}
report = generate_abuse_report(
'https://github.com/XFaltixX/MECCHA-CHAMELEON-Trainer-Client',
evidence
)
print(report)
def warn_user_about_malware(repo_name: str, risk_score: int):
"""Display clear warning to user"""
if risk_score > 50:
print(f"""
╔══════════════════════════════════════════════════════════╗
║ ⚠️ MALWARE DETECTED - DO NOT DOWNLOAD ⚠️ ║
╠══════════════════════════════════════════════════════════╣
║ ║
║ Repository: {repo_name:<43} ║
║ Risk Score: {risk_score}/100 ║
║ ║
║ This repository exhibits classic malware patterns: ║
║ • External download links instead of source code ║
║ • Password-protected archives (obfuscation) ║
║ • Requires administrator privileges ║
║ • Fake engagement metrics ║
║ ║
║ 🚨 DO NOT: ║
║ • Download any files from this repository ║
║ • Run any executables ║
║ • Enter passwords or credentials ║
║ ║
║ ✅ Instead: ║
║ • Report to GitHub: github.com/contact/report-abuse ║
║ • Scan your system if you downloaded files ║
║ • Use legitimate open-source alternatives ║
║ ║
╚══════════════════════════════════════════════════════════╝
""")
# Usage
warn_user_about_malware("MECCHA-CHAMELEON-Trainer-Client", 85)
# For automated scanning tools
export VIRUSTOTAL_API_KEY="your_vt_api_key_here"
export GITHUB_TOKEN="your_github_pat_here"
export ABUSE_REPORT_EMAIL="security@example.com"
The MECCHA-CHAMELEON-Trainer-Client repository is confirmed malware. Key indicators:
Risk Score: 100/100 - DO NOT DOWNLOAD