Skip to content
#

supply-chain-attack

Here are 43 public repositories matching this topic...

thumper

Thumper is an open-source tripwire for the Shai-Hulud npm worm. Plant fake-but-realistic credentials where the worm scans - the instant one is read, you know the box might be breached. Free and built in the open by Jesta.

  • Updated Sep 9, 2026
  • Python

GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.

  • Updated Sep 14, 2026
  • TypeScript

Supply-chain malware scanner for Git repos. Finds droppers committed into the repo itself — the kind npm audit can't see because there's no malicious dependency. Runs on git clone or when VS Code opens the folder. Kills the loader, scans every repo you can reach, purges it from history.

  • Updated Sep 10, 2026
  • Shell

Sentinel Package Manager blocks compromised packages BEFORE installation, preventing malicious code execution. Features: Pre-install blocking, command interception (npm/yarn/pnpm/bun), 795+ blacklist (Shai-Hulud), real-time checks (OSV/GitHub/Snyk), zero dependencies, auto-updates. Counters supply chain attacks.

  • Updated Dec 2, 2025
  • JavaScript

Educational demo showing how a trusted remote PowerShell script can be silently swapped when served from a mutable source URL. The import tutorial at wuwatracker.com does NOT do this and uses hashed URLs instead to prevent this attack.

  • Updated Mar 4, 2026
  • PowerShell

🛡️ Advanced NPM supply chain attack detection tool - Specialized in detecting Shai-Hulud compromise indicators with beautiful CLI interface and automated security reporting

  • Updated Sep 19, 2025
  • TypeScript
polinrider-cleaner

Detect and clean up after the PolinRider supply-chain campaign — GitHub organizations, personal accounts, and macOS/Linux/Windows machines. Shell only, dry-run by default.

  • Updated Sep 14, 2026
  • Shell
tanstack-compromise-checker

Add this topic to your repo

To associate your repository with the supply-chain-attack topic, visit your repo's landing page and select "manage topics."

Learn more