Scan local package-manager state for known supply-chain attack indicators.
Sha1-Hulud 2.0 npm supply chain attack scanner - Real-time detection using Koi.ai data
supply chain attack poc
Review dependencies changes to prevent supply chain attack
Detect and fix the mini-shai-hulud TanStack supply-chain attack (socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack)
Static obfuscation detector for npm lifecycle scripts — supply chain attack prevention
Supply chain attack protection audit tool for pnpm projects
npm supply chain attack defense via execution isolation
Security research backdoor package for supply chain attack simulation
Detect recently published npm packages in lockfiles for supply chain attack prevention
Inert test fixture for validating supply chain attack detection systems. Contains malicious code PATTERNS without actual harmful behavior.
Test fixture for np-audit — simulates a supply chain attack with obfuscated postinstall. Completely harmless.
Universal npm supply chain attack scanner. Detects compromised packages from 12+ known attacks.
A CLI tool for detecting the 'Shai-Hulud' npm supply chain attack that occurred in September 2025
Verdaccio middleware that blocks npm packages published less than N days ago, reducing supply-chain attack risk.
Scan your npm dependencies for supply chain attack indicators.
Detect malicious npm packages linked to the Shai-Hulud 2.0 supply chain attack.
Project integrity scanner for known vulnerabilities and suspicious patterns related to the Shai-Hulud supply-chain attack.
Detect recently published npm packages in lockfiles for supply chain attack prevention
Package used to demonstrate a supply chain attack.
Proof of concept for a dependency confusion supply chain attack.
Check if your GitHub repos were affected by the Sha1hulud supply chain attack
Scans your machine and Node.js projects for indicators of the axios supply chain attack
Proof of concept for a dependency confusion supply chain attack.
Sossy detects "risky" RubyGems packages in your software supply chain.
Ossie reports "risky" RubyGems packages in your software supply chain.
Packj flags malicious and other "risky" RubyGems packages in your software supply chain.
Static analysis tool that scans RubyGems for indicators of supply chain compromise: malicious gemspecs, suspicious URLs, credential exfiltration, obfuscated payloads, and more.
A CLI tool that prevents installation of gem versions that are too new (e.g., <14 days old), helping protect against supply chain attacks.
This gem has been published by Aikido Security to help prevent supply chain attacks. It is not intended for direct use. Please use 'aikido-zen' instead.
This package exists to prevent name squatting and malicious supply chain attacks. The beachcomber client SDK is published as libbeachcomber. See https://beachcomber.sh