You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2.
Supply-chain attack scanner for the agent era. Triage in 30s with `npx patient-zero`, block malicious installs before postinstall runs, or drop into CI as a GitHub Action. Covers npm + Python + MCP agent configs. Free, MIT, no signup, no telemetry.
Read-only IoC scanner for the Virtualizor supply-chain compromise delivered through the August 2026 BGP hijack of 162.55.80.0/24. Detects the java-jre-update.service backdoor, attacker SSH keys and injected core files - and preserves evidence instead of deleting it.
Single-file bash scanner for the keyv/cacheable npm compromise — detects preinstall malware, IDE auto-run hooks and gh-token-monitor persistence. No dependencies, one YES/NO verdict.