{"adoption": {"forks": 558, "observed_at": "2026-08-28T04:08:39.299415+00:00", "stars": 4254}, "canonical_url": "https://ross.abutalabs.com/products/malicious-pdf", "card": {"archived": false, "artifact_type": "cli-tool", "description": "💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh", "domain": ["security", "penetration-testing", "pdf"], "enriched": true, "function": ["pdf", "security", "penetration-testing", "web-scraping"], "health_score": 89, "homepage": null, "language": "Python", "license": "BSD-2-Clause", "license_family": "permissive", "maturity": "active", "member_repos": ["jonaslejon/malicious-pdf"], "name": "jonaslejon/malicious-pdf", "platform": ["python", "cli", "cross-platform"], "pushed_at": "2026-06-04T11:56:10+00:00", "repo": "jonaslejon/malicious-pdf", "stars": 4254, "tags": ["pentesting", "bugbounty", "redteam", "ssrf", "xss", "ntlm", "pdf-generation", "burp-collaborator", "interactsh"], "topics": ["penetrationtesting", "pentesting", "pentesting-tools", "penetration-testing", "penetration-test", "pdf-generation", "pdf", "bugbounty", "bugbounty-tool", "python", "redteam", "redteaming", "scanner"], "urls": [], "use_cases": ["generate malicious pdf files to test ssrf in pdf upload endpoints", "test pdf-to-image converters for blind callbacks", "check pdf viewers for xss and ntlm credential leaks", "bug bounty hunting on file upload endpoints accepting pdfs", "test server-side pdf processing libraries like pdfbox or itext", "evade naive /JS regex scanners with obfuscated pdf payloads", "verify security products detect malicious pdf documents"], "what_it_is": "A Python CLI tool that generates 67 malicious PDF test files embedding callbacks for SSRF, XSS, XXE, NTLM credential theft, and data exfiltration. It integrates with Burp Collaborator or Interact.sh to detect phone-home behavior in PDF viewers, converters, and web applications.", "when_to_avoid": ["you need a general-purpose PDF library for creating legitimate documents", "you lack authorization to test the target system", "you need a GUI-based PDF analysis or forensics tool"], "when_to_choose": ["you need a quick corpus of attack PDFs for authorized pentesting or bug bounty work", "you want to detect out-of-band callbacks from PDF processing pipelines using Collaborator or Interact.sh", "you need configurable obfuscation to test static analysis tools"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/malicious-pdf", "repo": "jonaslejon/malicious-pdf", "role": "main", "score": 86}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:08:39.299415+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T18:22:09.769259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aa4a78a55b8f3deb6f7f3c16aef4cbcc8941d9212e6bc962651bcd2ee02f83d2", "fetched_at": "2026-08-28T04:08:39.299415+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jonaslejon/malicious-pdf"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 85, "longevity": 100, "rhythm": 80}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1842, "days_push": 90, "days_rel": 135, "gap_med": 0, "n_releases_24m": 2}, "score": 86, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}