Ross ROSS = Recommend OSS · open-source software intelligence for agents

jonaslejon/malicious-pdf

💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh observed · 2026-08-28

github.com/jonaslejon/malicious-pdf · Python · BSD-2-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

86/100

  • Activity 85
  • Release rhythm 80
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 0
  • age_days: 1842
  • days_rel: 135
  • days_push: 90
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

4254 stars · 558 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A Python CLI tool that generates 67 malicious PDF test files embedding callbacks for SSRF, XSS, XXE, NTLM credential theft, and data exfiltration. It integrates with Burp Collaborator or Interact.sh to detect phone-home behavior in PDF viewers, converters, and web applications.

Use cases

  • generate malicious pdf files to test ssrf in pdf upload endpoints
  • test pdf-to-image converters for blind callbacks
  • check pdf viewers for xss and ntlm credential leaks
  • bug bounty hunting on file upload endpoints accepting pdfs
  • test server-side pdf processing libraries like pdfbox or itext
  • evade naive /JS regex scanners with obfuscated pdf payloads
  • verify security products detect malicious pdf documents

When to choose

  • you need a quick corpus of attack PDFs for authorized pentesting or bug bounty work
  • you want to detect out-of-band callbacks from PDF processing pipelines using Collaborator or Interact.sh
  • you need configurable obfuscation to test static analysis tools

When to avoid

  • you need a general-purpose PDF library for creating legitimate documents
  • you lack authorization to test the target system
  • you need a GUI-based PDF analysis or forensics tool

Facets

cli-tool · maturity active

pdf security penetration-testing web-scraping security penetration-testing pdf python cli cross-platform pentesting bugbounty redteam ssrf xss ntlm pdf-generation burp-collaborator interactsh

1 source

Member repositories

RepositoryRoleHealth v2
jonaslejon/malicious-pdfmain86

For agents

markdown · JSON · MCP: product_card(name="jonaslejon/malicious-pdf")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem