gensecaihq / Shai-Hulud-2.0-Detector Star 109 Code Issues Pull requests Discussions Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support. nodejs npm security sarif devsecops vulnerability-scanner malware-detection credential-theft github-actions open-source-security supply-chain-security sarif-report package-security shai-hulud shai-hulud-detector shai-hulud-attack shai-hulud2-detector shai-hulud2 shai-hulud2-inspector sha1-hulud Updated Dec 9, 2025 TypeScript
Security-Phoenix-demo / Shai-Hulud-Sha1-Hulud-V2-npm-compromise-scanner Star 12 Code Issues Pull requests Script to verify if Shai Hulud and Sha1-Hulud NPM package alike are affecting your NPM Build - check https://phoenix.security/shai-hulud-second-coming-npms-biggest-supply-chain-breach/ supply shai-hulud shai-hulud-detector shai-hulud-attack shai-hulud2-detector shai-hulud2 Updated Nov 26, 2025 Python
josedacosta / shai-hulud-detector Star 2 Code Issues Pull requests 🛡️ Advanced NPM supply chain attack detection tool - Specialized in detecting Shai-Hulud compromise indicators with beautiful CLI interface and automated security reporting threat-hunting vulnerability-detection security-analysis malware-detection defensive-security npm-audit malicious-packages compromise-detection crypto-stealer npm-security shai-hulud shai-hulud-detector shai-hulud-attack supply-chain-attack self-replicating-worm github-actions-malware bundle-js-detection trufflehog-abuse cli-security-tool package-scanner Updated Sep 19, 2025 TypeScript