# jonaslejon/malicious-pdf

💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh

Repository: https://github.com/jonaslejon/malicious-pdf
Canonical: https://ross.abutalabs.com/products/malicious-pdf
Language: Python
License: BSD-2-Clause
License Family: permissive
Topics: penetrationtesting, pentesting, pentesting-tools, penetration-testing, penetration-test, pdf-generation, pdf, bugbounty, bugbounty-tool, python, redteam, redteaming, scanner
Last push: 2026-06-04T11:56:10+00:00

## Health v2 (maintenance only)
Score: 86/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 85, release rhythm 80, longevity 100
- inputs: {"age_days": 1842, "days_push": 90, "days_rel": 135, "gap_med": 0, "n_releases_24m": 2}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4254, forks 558 (observed 2026-08-28T04:08:39.299415+00:00)

## What it is
A Python CLI tool that generates 67 malicious PDF test files embedding callbacks for SSRF, XSS, XXE, NTLM credential theft, and data exfiltration. It integrates with Burp Collaborator or Interact.sh to detect phone-home behavior in PDF viewers, converters, and web applications.

## Use cases
- generate malicious pdf files to test ssrf in pdf upload endpoints
- test pdf-to-image converters for blind callbacks
- check pdf viewers for xss and ntlm credential leaks
- bug bounty hunting on file upload endpoints accepting pdfs
- test server-side pdf processing libraries like pdfbox or itext
- evade naive /JS regex scanners with obfuscated pdf payloads
- verify security products detect malicious pdf documents

## When to choose
- you need a quick corpus of attack PDFs for authorized pentesting or bug bounty work
- you want to detect out-of-band callbacks from PDF processing pipelines using Collaborator or Interact.sh
- you need configurable obfuscation to test static analysis tools

## When to avoid
- you need a general-purpose PDF library for creating legitimate documents
- you lack authorization to test the target system
- you need a GUI-based PDF analysis or forensics tool

## Facets
- artifact type: cli-tool
- maturity: active
- function: pdf, security, penetration-testing, web-scraping
- domain: security, penetration-testing, pdf
- platform: python, cli, cross-platform
- tags: pentesting, bugbounty, redteam, ssrf, xss, ntlm, pdf-generation, burp-collaborator, interactsh

## Member repositories
- jonaslejon/malicious-pdf (main) score 86

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:39.299415+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:22:09.769259+00:00, confidence not recorded.
  - readme: https://github.com/jonaslejon/malicious-pdf (fetched 2026-08-28T04:08:39.299415+00:00, sha aa4a78a55b8f)
- Data as of 2026-08-30T08:39:29.467469+00:00.
