ActionRank

Shai-Hulud 2.0 Detector

Stale

gensecaihq/Shai-Hulud-2.0-Detector · MIT

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

144 starsLast commit 5 months agoLatest v2.1.0
B
70
/ 100
Security 100Maintenance 60Popularity 41Reliability 58

Security signals

OpenSSF ScorecardNo data
SECURITY.md presentYes
Immutable releasesEnabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: gensecaihq/Shai-Hulud-2.0-Detector@e42b26d04fb7a7a9872e6b9f449f65f9b36aba98 # v2.1.0

Mutable tags like v2.1.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: gensecaihq/Shai-Hulud-2.0-Detector@e42b26d04fb7a7a9872e6b9f449f65f9b36aba98 # v2.1.0

Score breakdown

Security (35%)100
Popularity (20%)41
Maintenance (30%)60
Reliability (15%)58