Skip to content

Instantly share code, notes, and snippets.

View xpicio's full-sized avatar

Patrizio Bertozzi xpicio

View GitHub Profile
@xpicio
xpicio / check-shai-hulud.sh
Last active November 25, 2025 15:02
Scans Node.js projects for potentially compromised packages from the Shai-Hulud 2.0 attack
#!/usr/bin/env bash
# =============================================================================
# Shai-Hulud 2.0 Supply Chain Attack Scanner
# =============================================================================
# Scans Node.js projects for potentially compromised packages from the
# Shai-Hulud 2.0 attack documented at:
# https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
#
# Uses Trivy (via Docker) to parse lockfiles and generate SBOM