GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
nodejs npm security ioc sarif devsecops code-scanning malware-detection threat-detection credential-theft github-actions github-action dependency-scanning open-source-security supply-chain-security npm-security shai-hulud supply-chain-attack chaindrop shai-hulud-2
-
Updated
Sep 5, 2026 - TypeScript