Shai-Hulud 2.0 Detector
Actively maintainedgensecaihq/Shai-Hulud-2.0-Detector · MIT
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
★ 150 starsLast commit 1 months agoLatest v2.2.0
B
81
/ 100
Security signals
OpenSSF ScorecardNo data
SECURITY.md presentYes
Immutable releasesEnabled
Known vulnerabilitiesNone on record
How to use it safely
Recommended: pin to commit SHA
uses: gensecaihq/Shai-Hulud-2.0-Detector@2755f94762bf5012bc7be82c93e172eabbcd0802 # v2.2.0Mutable tags like v2.2.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.
Full workflow example
steps: - uses: gensecaihq/Shai-Hulud-2.0-Detector@2755f94762bf5012bc7be82c93e172eabbcd0802 # v2.2.0
Score breakdown
Security (35%)100
Popularity (20%)42
Maintenance (30%)96
Reliability (15%)58
Add this badge to your README
Markdown
[](https://actionrank.dev/actions/gensecaihq-shai-hulud-2-0-detector)HTML version
HTML
<a href="https://actionrank.dev/actions/gensecaihq-shai-hulud-2-0-detector"><img src="https://actionrank.dev/api/badge/gensecaihq-shai-hulud-2-0-detector" alt="ActionRank score"></a>Free to use, no attribution required — the badge updates itself as the score changes. How badges work