Skip to content
#

sha1-hulud

Here are 6 public repositories matching this topic...

Language: All
Filter by language

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Dec 28, 2025
  • TypeScript

🛡️ Detect Shai Hulud npm-worm compromises in GitHub users and organizations with this easy-to-use CLI tool, protecting your code from malicious attacks.

  • Updated Dec 28, 2025
  • Python

Improve this page

Add a description, image, and links to the sha1-hulud topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the sha1-hulud topic, visit your repo's landing page and select "manage topics."

Learn more