ptoomey3/evilarc
Create tar/zip archives that can exploit directory traversal vulnerabilities observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 5666
- days_rel: n/a
- days_push: 1917
- n_releases_24m: 0
Adoption not part of the score
1055 stars · 188 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
evilarc is a Python CLI tool that creates tar and zip archives containing files with directory traversal characters in their embedded paths. It is used to generate malicious archives that exploit vulnerable extraction libraries to write files to arbitrary locations on a target system.
Use cases
- create zip files that exploit directory traversal on extraction
- test whether an application is vulnerable to zip slip
- generate malicious tar archives for penetration testing
- demonstrate archive extraction vulnerabilities in Java or PHP libraries
- craft archives that write files outside the extraction directory
When to choose
- you are penetration testing or security researching archive extraction flaws
- you need to test whether your own code safely handles malicious zip/tar paths
- you want a simple Python tool to craft traversal archives
When to avoid
- you need a general-purpose archive creation tool
- you require a maintained project with an explicit license and active releases
- you need protection against zip slip rather than a way to demonstrate it
Facets
cli-tool · maturity maintenance
security cli compression security penetration-testing developer-tools python cli cross-platform zip-slip directory-traversal archive-exploitation penetration-testing-tool
1 source
- readme: https://github.com/ptoomey3/evilarc · fetched 2026-08-28 · 9b6ca58a025d
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| ptoomey3/evilarc | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="ptoomey3/evilarc")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem