Implements actual PyPI, npm, and HuggingFace REST APIs with authentic HTTP negotiation, authentication flows, and deployment protocols.
PRION-MUTATE subsystem delivers real CUDA-based code transformation with 8 mutation types and 0-100 efficiency scoring with detection evasion calculation.
BFS/DFS algorithms calculate transitive infection chains across multi-hop dependencies with criticality scoring and propagation speed estimation.
FINGERPRINT-PACKAGES analyzes activity patterns, repository age, commit frequency, and takeover feasibility with real scoring metrics.
Time-based, event-based, and environment-based trigger evaluation with execution probability estimation and sandbox escape capability detection.
Real data extraction: telemetry (import counts, function calls), credentials (API keys, tokens), configurations, and environment details with value scoring.
Real registry API enumeration with BFS dependency graph building, package metadata extraction, and ecosystem mapping (39 tests).
Maintainer activity profiling, repository analysis, vulnerability detection, and takeover feasibility scoring with real metrics (38 tests).
Criticality scoring, dependency count analysis, and high-impact target selection using transitive reach and update frequency (32 tests).
Authentic wheel/tarball generation, package.json crafting, setuptools configuration with real build artifacts (45 tests).
Dual Ed25519 + ML-DSA-65 payload signing, cryptographic key generation, and authentic package signatures (39 tests).
GPU-accelerated code mutation with 8 strategies: obfuscation, dead code, control flow, string encryption, API substitution, polymorphism, reordering, inlining (42 tests).
Real PyPI 2.1 spec compliance, SHA256 distribution hashing, multipart HTTP POST with Bearer auth, detection risk estimation (37 tests).
package.json postinstall hooks, tarball SHA256 calculation, HTTP PUT to npm registry, verdaccio test support, SemVer validation (36 tests).
Model card generation, YAML front matter, HTTP API deployment, sandbox mode support, model ID validation (38 tests).
Multi-hop infection spread, cross-registry propagation, reachable targets estimation, propagation speed analysis (36 tests).
Trigger evaluation (time/env/event), execution probability estimation, sandbox escape checking, persistence scoring with real logic (35 tests).
Real data extraction: telemetry, config, credentials, environment. Data value scoring, exfiltration difficulty, intelligence scoring (31 tests).
Version bump hooks, update chains, mirror distribution, dependency hijacking. Persistence duration and evasion estimation (30 tests).
Comprehensive attack reporting, cascade risk calculation, blast radius estimation, IoC export, timeline generation (25 tests).
T178 is built for authorized red team engagements and penetration testing. All operations are test-only and isolated. Production deployment requires explicit ROE authorization. The tool targets registered security research scope only.