Skip to content
#

package-security

Here are 10 public repositories matching this topic...

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Dec 8, 2025
  • TypeScript

CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.

  • Updated Dec 8, 2025
  • Go

Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.

  • Updated Dec 8, 2025
  • JavaScript

Improve this page

Add a description, image, and links to the package-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the package-security topic, visit your repo's landing page and select "manage topics."

Learn more