sighook/pixload
Image Payload Creating/Injecting tools observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2545
- days_rel: n/a
- days_push: 1007
- n_releases_24m: 0
Adoption not part of the score
1300 stars · 251 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
pixload is a set of Perl CLI tools for creating and injecting payloads into image files (BMP, GIF, JPG, PNG, WebP). It is used in offensive security testing to craft polyglot images that hide malicious code such as web shells or metasploit payloads.
Use cases
- inject a web shell payload into a png image
- create polyglot jpeg images to bypass CSP
- hide metasploit payloads inside image files
- test image upload filters for security vulnerabilities
- embed xss payloads in png IDAT chunks
- generate malicious images for penetration testing
When to choose
- you need to test whether an application's image upload pipeline properly sanitizes files
- you want to craft polyglot image payloads for authorized penetration tests or security research
When to avoid
- you need general-purpose image editing or conversion
- you are looking for defensive malware analysis tooling rather than offensive payload generation
Facets
cli-tool · maturity active
security image-processing penetration-testing security penetration-testing image-processing bsd cli payload-injection polyglot-files web-shells offensive-security perl linux macos docker
1 source
- readme: https://github.com/sighook/pixload · fetched 2026-08-28 · f431e91d5133
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| sighook/pixload | main | 23 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem