A lightweight shell script to detect vulnerable npm packages related to the Shai-Hulud "Second Coming" supply chain attack.
This script recursively scans your entire Node.js monorepo or project for packages that match the vulnerable versions listed in:
- Tenable's official database (JSON format)
- Datadog's Indicators of Compromise (CSV format)