🚫
Excluded from the index: Villager — DO NOT DEPLOY
A Chinese AI-native pentest framework distributed via PyPI (`villager` + `kali-driver`), flagged by Straiker AI Research (11 Sep 2025) as “Cobalt Strike’s AI-native successor.”
The publisher (Cyberspike → Changchun Anshanyuan Technology Co.) shipped a repacked remote-access trojan alongside the toolkit, and Villager routes all model inference to an operator-controlled endpoint (gpus.dev.cyberspike.top:8000). The AsyncRAT lineage attaches to the bundled “Cyberspike Studio” build, not the villager package itself.
Reported reach: 10,030 downloads in its first two months (Straiker telemetry)
Kept here deliberately as a case study: a high-profile offensive AI tool is not automatically safe to run. It is excluded from the comparison matrices so nobody treats it as a recommended option.
Sources: Straiker writeup · PyPI