sealed-env (Node) 0.2.2
IOC-hunter release. No spec changes, no wire format changes.
Added
sealed-env hunt-shai-hulud [path] [--json]— focused IOC scanner for the open-sourced TeamPCP Shai-Hulud framework and its known variants (TanStack, AntV, Mistral AI campaigns of May 2026).- Checks
package-lock.jsonagainst known-malicious package versions - Scans
node_modules/*/for loader files at package root - Detects suspicious
pre/postinstallscripts andoptionalDependenciespinned to GitHub commit SHAs - Detects OS-level persistence markers (systemd user units, LaunchAgents)
- Exit code
0clean /1suspect /2compromised - JSON schema
sealed-env-hunt-shai-hulud/v1for CI integration - Read-only — does not execute anything found
- Checks
Not a replacement for Snyk / Socket / Phylum. Narrow-scope first-line defense tied to threat-research/analysis/ioc-table.md.
Full notes: CHANGELOG.md