$npx skillfedfor your agent

malduck

Malduck is your ducky companion in malware analysis journeys

With conditionsPyPI SecurityReleased May 202489.0K downloads / moGPLv3Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — malduck-4.4.1-py3-none-any.whl
v4.4.1 · released 2024-05-10 · Python >=3.8 · 9 runtime deps: capstone, click, cryptography, dnfile, pefile, pycryptodomex, pyelftools, typing-extensions

Yes, if you are doing malware analysis or reverse engineering and need a compact toolkit for cryptography, decompression, and memory parsing. The copyleft license is acceptable for research and internal tools but problematic for closed-source products. Maintenance is aging (last release over a year ago), so expect to maintain patches yourself if critical issues arise, but the codebase is stable and no known vulnerabilities are recorded.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.8 or later; yara-python and pycryptodomex are compiled dependencies that may require build tools on some systems.
  • Low install friction with a pure-Python wheel.
  • Maintenance is aging—last release was 2024-05-10, over a year ago—but the repository remains active with recent commits and no archived status.

License · maintenance · safety

GPLv3 (copyleft) — GPLv3 copyleft license requires that any derivative work or distribution must also be licensed under GPLv3 and provide source code; suitable for internal malware research but restrictive for closed-source commercial tools.

last release 2024-05-10 (826 days) · last repo commit 2025-06-22 · 357 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 88,995 downloads/mo, #13,688 on PyPI

Verify before relying

pip install malduck

from malduck import aes

key = b'A'*16
iv = b'B'*16
plaintext = b'data'*16
ciphertext = aes.cbc.encrypt(key, iv, plaintext)
  • Whether yara-python and other binary dependencies install smoothly on Windows and macOS without additional setup.
  • Current maintenance cadence and likelihood of future updates beyond the 2024-05-10 release.
Same gist for agents: .md · .json

What it is and what it does

Malduck is a Python library for malware analysis that bundles cryptographic primitives (AES, Blowfish, ChaCha20, Serpent), compression algorithms (aPLib, gzip, LZNT1), and memory-model abstractions to work uniformly across PE executables, ELF binaries, raw memory dumps, and IDA output. It originated as a fork of the Roach project to decouple it from Cuckoo Sandbox while retaining support for Cuckoo's procmem format.

The library is designed to reduce boilerplate in malware research scripts by providing fixed-width integer types, string utilities, hashing functions, and a modular extraction engine for config recovery. You work with memory or binary objects using the same API regardless of source format, and can define custom extractors using YARA rules and pattern matching to identify and parse malware families.

Use it for

  • Decrypt and analyze malware communications encrypted with AES, Blowfish, or ChaCha20.
  • Decompress packed malware samples using aPLib or LZNT1 algorithms.
  • Extract configuration data from memory dumps or PE files using the Extractor framework with YARA rules.
  • Parse and inspect PE and ELF binaries and memory dumps with a unified memory-model API.
  • Implement custom malware family signatures and extraction logic for automated analysis pipelines.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are doing malware analysis or reverse engineering and need a compact toolkit for cryptography, decompression, and memory parsing.

The copyleft license is acceptable for research and internal tools but problematic for closed-source products. Maintenance is aging (last release over a year ago), so expect to maintain patches yourself if critical issues arise, but the codebase is stable and no known vulnerabilities are recorded.

Install

malduck on PyPI

Before you install

Low install friction with a pure-Python wheel. Maintenance is aging—last release was 2024-05-10, over a year ago—but the repository remains active with recent commits and no archived status.

Requires Python 3.8 or later; yara-python and pycryptodomex are compiled dependencies that may require build tools on some systems.

License in practice

GPLv3 copyleft license requires that any derivative work or distribution must also be licensed under GPLv3 and provide source code; suitable for internal malware research but restrictive for closed-source commercial tools.

Quickstart

pip install malduck

from malduck import aes

key = b'A'*16
iv = b'B'*16
plaintext = b'data'*16
ciphertext = aes.cbc.encrypt(key, iv, plaintext)

Verify before relying

  • Whether yara-python and other binary dependencies install smoothly on Windows and macOS without additional setup.
  • Current maintenance cadence and likelihood of future updates beyond the 2024-05-10 release.

Package facts

LicenseGPLv3 copyleft
Python supportSupports the current Python release >=3.8
Install frictionLow. Pure-Python wheel
Runtime dependencies
9 packages
capstoneclickcryptographydnfilepefilepycryptodomexpyelftoolstyping-extensionsyara-python
MaintenanceAging 826 days since the last release
Last repo commit
First released
Downloads88,995 / month, #13,688 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Operating System :: POSIX :: LinuxProgramming Language :: Python :: 3

Evidence: malduck-4.4.1-py3-none-any.whl

Tags

Capabilities
malware analysis toolkitcryptography utilitiesbinary memory analysisPE ELF parsingcompression decompressionconfig extraction malwareyara integration analysis
Topics
malware-analysisreverse-engineeringcryptography

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “malware analysis toolkit”

  • malduckMalduck provides cryptographic, compression, and memory-analysis…
  • oletoolsoletools is a suite of Python tools to extract, analyze, and detect…
  • viv-utilsProvides utility functions and helpers for analyzing and manipulating…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also deflate · maco-extractor · eth-keyfile · membrowse · esp-coredump · ropper · lief · binsize · yara-x · ROPGadget