Skip to content
#

shai-hulud2

Here are 4 public repositories matching this topic...

Language: All
Filter by language

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Dec 8, 2025
  • TypeScript

Improve this page

Add a description, image, and links to the shai-hulud2 topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the shai-hulud2 topic, visit your repo's landing page and select "manage topics."

Learn more