Skip to content
#

package-security

Here are 30 public repositories matching this topic...

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Jun 7, 2026
  • TypeScript

CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.

  • Updated Apr 14, 2026
  • Go

Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.

  • Updated Jun 5, 2026
  • JavaScript

oh supply chain my supply chain — a multi-ecosystem package malware scanner for PyPI, npm, crates.io, and Go. Static analysis plus a sandbox detonation engine, with pluggable detection content (open-core; AGPL engine, Apache-2.0 signatures).

  • Updated Jun 3, 2026
  • Python

Improve this page

Add a description, image, and links to the package-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the package-security topic, visit your repo's landing page and select "manage topics."

Learn more