Skip to content
#

chaindrop

Here are 4 public repositories matching this topic...

Language: All
Filter by language

GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.

  • Updated Aug 11, 2026
  • TypeScript

Comprehensive detection tool for NPM supply chain attacks, specifically designed to identify and prevent the Shai-Hulud worm and Shai-Hulud 2-0-0 that compromised 1193+ packages including CrowdStrike npm packages in 2025.

  • Updated Aug 7, 2026
  • Python

Shai-Hulud/ChainDrop npm worm scanner — 220 tests, zero deps, cross-platform. Detects 416 poisoned packages: lockfile analysis, SHA-256 hashes, content markers, credential audit, persistence. ReDoS-safe, thread-safe, SARIF output. Production-ready supply-chain defense.

  • Updated Aug 8, 2026
  • Python

Improve this page

Add a description, image, and links to the chaindrop topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the chaindrop topic, visit your repo's landing page and select "manage topics."

Learn more