Skip to content
#

npm-security

Here are 68 public repositories matching this topic...

thumper

Thumper is an open-source tripwire for the Shai-Hulud npm worm. Plant fake-but-realistic credentials where the worm scans - the instant one is read, you know the box might be breached. Free and built in the open by Jesta.

  • Updated Aug 26, 2026
  • Python

GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.

  • Updated Aug 31, 2026
  • TypeScript

macOS Seatbelt sandbox CLI for developers. Protect credentials (SSH, AWS, GPG) from malicious npm packages, supply chain attacks, and untrusted build scripts. Deny-by-default filesystem isolation. Perfect for Claude Code agentic workflows with --dangerously-skip-permissions.

  • Updated Aug 22, 2026
  • Rust

Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.

  • Updated Aug 29, 2026
  • JavaScript

Sentinel Package Manager blocks compromised packages BEFORE installation, preventing malicious code execution. Features: Pre-install blocking, command interception (npm/yarn/pnpm/bun), 795+ blacklist (Shai-Hulud), real-time checks (OSV/GitHub/Snyk), zero dependencies, auto-updates. Counters supply chain attacks.

  • Updated Dec 2, 2025
  • JavaScript

Defensive static analysis and detection engineering for the 2026 Shai-Hulud npm supply-chain campaign: Sigma/YARA rules, IOCs, ATT&CK mapping, and defender guidance.

  • Updated Aug 4, 2026
  • YARA

Supply-chain malware scanner for Git repos. Finds droppers committed into the repo itself — the kind npm audit can't see because there's no malicious dependency. Runs on git clone or when VS Code opens the folder. Kills the loader, scans every repo you can reach, purges it from history.

  • Updated Aug 29, 2026
  • Shell
supply-chain-mcp-server

90-tool MCP server for software supply chain security — OSV, GHSA, NVD, EPSS, CISA KEV, npm, PyPI, crates.io, RubyGems, NuGet, Packagist, Go, deps.dev, Scorecard, Rekor, ClearlyDefined, Repology, typosquatting detection

  • Updated Aug 12, 2026
  • TypeScript

Security scanner for MCP (Model Context Protocol) servers. Detect prompt injection, secrets leaks, supply chain attacks, and vulnerabilities in MCP servers. CLI + MCP server mode.

  • Updated Aug 2, 2026
  • TypeScript

Improve this page

Add a description, image, and links to the npm-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the npm-security topic, visit your repo's landing page and select "manage topics."

Learn more