Skip to content
#

shai-hulud

Here are 21 public repositories matching this topic...

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Dec 9, 2025
  • TypeScript

Comprehensive detection tool for NPM supply chain attacks, specifically designed to identify and prevent the Shai-Hulud worm and Shai-Hulud 2-0-0 that compromised 1193+ packages including CrowdStrike npm packages in 2025.

  • Updated Dec 5, 2025
  • Python

Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.

  • Updated Dec 8, 2025
  • JavaScript

Sentinel Package Manager blocks compromised packages BEFORE installation, preventing malicious code execution. Features: Pre-install blocking, command interception (npm/yarn/pnpm/bun), 795+ blacklist (Shai-Hulud), real-time checks (OSV/GitHub/Snyk), zero dependencies, auto-updates. Counters supply chain attacks.

  • Updated Dec 2, 2025
  • JavaScript

🛡️ Advanced NPM supply chain attack detection tool - Specialized in detecting Shai-Hulud compromise indicators with beautiful CLI interface and automated security reporting

  • Updated Sep 19, 2025
  • TypeScript

Improve this page

Add a description, image, and links to the shai-hulud topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the shai-hulud topic, visit your repo's landing page and select "manage topics."

Learn more