Shai-Hulud 2.0 Detector
Stalegensecaihq/Shai-Hulud-2.0-Detector · MIT
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
★ 144 starsLast commit 5 months agoLatest v2.1.0
B
70
/ 100
Security signals
OpenSSF ScorecardNo data
SECURITY.md presentYes
Immutable releasesEnabled
Known vulnerabilitiesNone on record
How to use it safely
Recommended: pin to commit SHA
uses: gensecaihq/Shai-Hulud-2.0-Detector@e42b26d04fb7a7a9872e6b9f449f65f9b36aba98 # v2.1.0Mutable tags like v2.1.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.
Full workflow example
steps: - uses: gensecaihq/Shai-Hulud-2.0-Detector@e42b26d04fb7a7a9872e6b9f449f65f9b36aba98 # v2.1.0
Score breakdown
Security (35%)100
Popularity (20%)41
Maintenance (30%)61
Reliability (15%)58