USB Rubber Ducky Payload Library: Community DuckyScript Payloads for Keystroke Injection
The Official USB Rubber Ducky Payload Repository
At a glance
- What is it?
- The Hak5 USB Rubber Ducky Payload Repository is the official community collection of DuckyScript payloads for the USB Rubber Ducky keystroke injection device. Payloads are written in DuckyScript and must be compiled with Hak5 PayloadStudio before deployment on the hardware. The repository covers Windows, macOS, and Linux targets.
- Who is it for?
- The USB Rubber Ducky payload repository is the right starting point for security professionals, IT administrators, and researchers who own the Hak5 USB Rubber Ducky and want ready-made or community-contributed DuckyScript payloads. Payloads in this repository require Hak5 PayloadStudio to compile and will not run on third-party keystroke injection devices.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository last received commits 30 days ago.
- What is it written in?
- Mainly PowerShell, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What the USB Rubber Ducky Does
The USB Rubber Ducky is a hardware device by Hak5 that presents itself to computers as a USB keyboard. Operating systems trust keyboards implicitly through the Human Interface Device (HID) standard; when the Rubber Ducky is plugged into a computer, the system treats it as a legitimate keyboard input source. The device then injects keystrokes at speeds far exceeding human typing, executing payloads that can automate any task achievable through keyboard input. This technique was introduced by Hak5 founder Darren Kitchen in 2010 for automating routine IT tasks. The device has since become a standard tool in penetration testing and security research. The repository does not contain the hardware or its firmware; it holds only the DuckyScript payload files used to program what the device types.
DuckyScript 3.0 and What Changed from 1.0
The original DuckyScript (1.0) launched with three commands and was designed to be learned in minutes. The new USB Rubber Ducky released in 2022 introduced DuckyScript 3.0, a structured programming language that is backwards compatible with all DuckyScript 1.0 payloads. DuckyScript 3.0 adds control flow constructs, loops, and functions for writing more complex payloads without duplicating lines. New keystroke injection features include OS Detection, which allows a single payload to branch into different code paths for Windows, macOS, or Linux based on what the target system is. Keystroke Reflection is a DuckyScript 3.0 feature that allows the device to read characters from the target machine's keyboard input during execution, enabling adaptive payloads that respond to the target's state. Extensions provide reusable code blocks that can be imported into multiple payloads.
Repository Layout and How to Use a Payload
The repository has two top-level directories: payloads/ and languages/. The payloads/ directory contains the community-contributed and officially maintained DuckyScript payload files organized by category or target platform. The languages/ directory provides keystroke layout files for different keyboard locales, which is necessary because keystroke injection sends raw key codes that are interpreted by the target keyboard layout; a payload that works on a US English keyboard may produce incorrect characters on a French or German layout.
Using a payload requires the Hak5 PayloadStudio tool. Open PayloadStudio, load the .txt or .dd DuckyScript source file, set the correct keyboard language, and compile it to a binary. Copy the resulting payload to the USB Rubber Ducky's storage partition. The README links to the PayloadStudio product page and to a quickstart guide at docs.hak5.org for the full workflow. No command-line compilation tool is available in this repository itself; all compilation is handled through PayloadStudio.
OS Detection and Multi-Platform Payloads
OS Detection in DuckyScript 3.0 allows a payload to identify whether the target is running Windows, macOS, or Linux before executing platform-specific commands. This is significant for the payload library because many payloads previously required a separate file for each target operating system. With OS Detection, a single payload file can open a terminal on Windows (PowerShell), macOS (Terminal.app), or Linux (a bash shell) using the appropriate keyboard shortcut for each platform. The repository includes both OS-specific payloads and multi-platform payloads that use OS Detection. Payloads targeting Windows typically use PowerShell, which is why the repository's primary language is listed as PowerShell; most payloads execute PowerShell commands via the Run dialog or a terminal spawned by keystroke sequences.
Limitations and Legal Boundaries
The payloads in this repository are designed exclusively for the Hak5 USB Rubber Ducky. They are written in DuckyScript and must be compiled using Hak5 PayloadStudio; they do not work on other keystroke injection devices such as cheap USB HID emulators that use different scripting dialects. Hak5 states explicitly in the README that it does not guarantee payload functionality, as targets vary in OS version, security configuration, and layout. Payloads that rely on specific keyboard shortcuts (for example, Win+R to open the Windows Run dialog) may fail if those shortcuts are blocked by group policy or remapped by the user. The legal boundary is unambiguous: keystroke injection on a device without authorization from its owner is illegal in most jurisdictions. This repository is intended for authorized testing, research, and IT automation.
Contributing Payloads and the PayloadHub Community
The README encourages developers to submit payloads via pull requests. A CONTRIBUTING.md file documents the requirements for a valid submission. Hak5 also maintains PayloadHub at payloadhub.com as a showcase for featured payloads, with a leaderboard and periodic payload awards that offer prizes. The community is active on Discord at hak5.org/discord and on the Hak5 forums. A payload submission becomes visible in the repository and may appear in the PayloadHub featured feed after review. The repository does not publish acceptance criteria beyond what CONTRIBUTING.md documents, so reading that file before writing a submission is necessary to understand what is required for a pull request to be merged.
Editorial conclusion
The USB Rubber Ducky payload repository is the right starting point for security professionals, IT administrators, and researchers who own the Hak5 USB Rubber Ducky and want ready-made or community-contributed DuckyScript payloads. Payloads in this repository require Hak5 PayloadStudio to compile and will not run on third-party keystroke injection devices. Hak5 does not guarantee payload functionality, and legal use requires authorization from the target system's owner. The repository is actively maintained: the last push was on 2026-09-01, and community submissions are accepted through pull requests.
Frequently asked questions
How fast can the USB Rubber Ducky type?
The README describes the device as injecting keystrokes at superhuman speeds. The specific typing rate is not documented in the repository; the Hak5 product documentation at docs.hak5.org covers hardware-level timing details.
Is rubber ducky illegal?
Using the USB Rubber Ducky against a computer without authorization from its owner is illegal in most jurisdictions. The device itself is a legal product sold by Hak5 for security research and IT automation. Authorization is the decisive factor.
What is a white ducky USB?
The README does not document a product called a white ducky USB. The Hak5 USB Rubber Ducky is the device this payload library is written for; it is available through the Hak5 shop. Third-party devices with similar form factors are not the same hardware.
What language is Ducky Script?
DuckyScript is a scripting language designed specifically for the Hak5 USB Rubber Ducky. DuckyScript 3.0, introduced with the 2022 hardware revision, is a structured language with control flow, loops, functions, and OS Detection. It is not related to any general-purpose programming language.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/hak5-usbrubberducky-payloads)