bsdtar -xf suspicious.zip To list contents without extraction:
You have an encrypted ZIP and one of its original unencrypted files (e.g., a README.txt or a default config).
7z a -p"secret" -mhe=on -tzip archive.zip folder/ The -mhe=on flag hides the file list (header encryption), something the standard zip command cannot do. When dealing with untrusted ZIP files (e.g., malware samples), you must extract safely without executing any embedded scripts or auto-run features.