Skip to main content

StegoFox Pro 🦊

High-performance encrypted steganography CLI.

More about me / other projects: abhrankan.netlify.app

Hide any file inside a PNG image using LSB (least-significant-bit) embedding, optionally encrypted with AES-256-GCM before it ever touches the pixels.

Features

  • LSB steganography — embed arbitrary binary data in a cover image's pixel data
  • Optional AES-256-GCM encryption (PBKDF2-HMAC-SHA256, 100k iterations) before embedding
  • Lossless PNG output — the embedding survives save/reload exactly
  • Wrong-password and corrupted-payload detection fail cleanly (no crash, no garbage output)
  • Capacity checking — refuses to embed data too large for the cover image, before touching anything, and prints an estimated capacity upfront

Install

pip install stegofox

Or from source:

git clone https://github.com/foxhackerzdevs/stegofox.git
cd stegofox
pip install -e .

Usage

stegofox embed cover.png secret.txt -o output.png
# With password protection -- omit the value to be prompted (recommended)
stegofox embed cover.png secret.txt -o output.png --password
# Password:
🦊 StegoFox Pro

📸 Loading cover image: cover.png
📏 Image capacity: ~2,400 bytes
🔐 Encrypting payload...
🧬 Embedding 712 bits...
✅ Successfully embedded! Saved to output.png
stegofox extract output.png --password
# Password:
🦊 StegoFox Pro

🔍 Analyzing output.png
🔓 Decrypting...
✅ Extracted 33 bytes
checking output messages exactly
# Wrong password fails cleanly, no crash
stegofox extract output.png --password
# Password: (wrong password entered)
🦊 StegoFox Pro

🔍 Analyzing output.png
🔓 Decrypting...
❌ Decryption failed. Wrong password?

--password <value> (passing it directly) is also accepted for scripted use, but prints a warning to stderr — the password is visible in shell history and to other local users via ps. Prefer the prompted form above for interactive use.

How it works

Each RGB channel byte of the cover image has its least-significant bit replaced with one bit of the payload. A 4-byte magic signature (SFOX) plus a 4-byte length header precede the payload so extraction knows exactly how much data to read back out. Output is always saved as PNG — a lossy format (JPEG, etc.) would destroy the embedded bits on save.

With --password, the payload is encrypted with AES-256-GCM (authenticated encryption) before embedding, so a wrong password fails the auth-tag check and returns a clean error rather than garbage bytes.

Security Notes

  • --password never touches CLI args when used interactively — omit the value to be prompted via getpass. The --password <value> form is still accepted for scripts, but leaks the password into shell history and ps.
  • Encryption is AES-256-GCM (authenticated) — a wrong password or corrupted payload fails the auth-tag check cleanly rather than returning garbage.
  • Key derivation is PBKDF2-HMAC-SHA256 at 100,000 iterations, not Argon2id. This is a known tradeoff, not an oversight: the iteration count isn't stored in the embedded payload, so changing it (or switching KDFs) would make every already-embedded image undecryptable with a newer version. Strengthening this later requires a self-describing payload format first — noted here rather than silently left undocumented.

Requirements

Python >= 3.8, pillow, numpy, pycryptodome.

License

MIT

Release files for stegofox 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for stegofox 0.2.0
File Size Uploaded
stegofox-0.2.0.tar.gz 7.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for stegofox 0.2.0
File Interpreter ABI Platform
stegofox-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 14.0 kB

Release files / stegofox-0.2.0.tar.gz

Download URL stegofox-0.2.0.tar.gz
Size 7.4 kB
Tags Source
SHA-256 checksum
How to use checksums
cb51e796a6ae689e58d9a32eed3970b7cecef14c6b7407fa863ea626abb6a73f
BLAKE2b-256 checksum
How to use checksums
6c167a3876254440131a11a51ac5ca86834d622ee790c2e64c44a0a4c19a154b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.12

Release files / stegofox-0.2.0-py3-none-any.whl

Download URL stegofox-0.2.0-py3-none-any.whl
Size 6.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a82e6fdf4f0fcd02be1974b13997dcee5e4f4740056edf3e59efff9001759a8b
BLAKE2b-256 checksum
How to use checksums
e9c3fd9e5d3923511b162d1ffc4bfffdd3b23541215544177178aede0a386dd4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.12

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page