{"_id":"@digi4care/shai-scan","_rev":"2-16017917213dd2433a66170657683350","name":"@digi4care/shai-scan","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@digi4care/shai-scan","version":"0.1.0","keywords":["security","supply-chain","npm","scanner","malware","shai-hulud","CVE-2026-45321"],"author":{"name":"Chris Engelhard"},"license":"MIT","_id":"@digi4care/shai-scan@0.1.0","maintainers":[{"name":"digi4care","email":"c.engelhard@digi4care.nl"}],"homepage":"https://github.com/digi4care/shai-scan#readme","bugs":{"url":"https://github.com/digi4care/shai-scan/issues"},"bin":{"shai-scan":"src/cli.ts"},"dist":{"shasum":"6e7412a9a0a723a1cffb0b2b5da1324ffc0382ab","tarball":"https://registry.npmjs.org/@digi4care/shai-scan/-/shai-scan-0.1.0.tgz","fileCount":8,"integrity":"sha512-VvrbyOMxDFehh040rOvsX2Zqt98585bDx6H0zc8VddB34D5hXwrSvgUcOdfYGA2V8zDPhvhvKVhH8HZQc9d48A==","signatures":[{"sig":"MEUCIBxga0gMRRJ4lvP2Qerjznykmb51o2zDoe0p+TOez3eZAiEAhkycnK+gCeR0itBNA6dE99RO+B+rCezLn67eVMj3blU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@digi4care%2fshai-scan@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":60412},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"5a31c03f52559b8800166b7f8a387b67dfc616ad","scripts":{"scan":"bun run src/cli.ts","check":"biome check src/","release":"bumpp && npm publish","check:fix":"biome check --fix src/"},"_npmUser":{"name":"digi4care","email":"c.engelhard@digi4care.nl"},"repository":{"url":"git+https://github.com/digi4care/shai-scan.git","type":"git"},"_npmVersion":"10.9.7","description":"Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like Mini Shai-Hulud (CVE-2026-45321).","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"packageManager":"pnpm@10.11.0","devDependencies":{"bumpp":"^10.1.0","typescript":"^5.8.0","@biomejs/biome":"^2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/shai-scan_0.1.0_1778936340712_0.4972491256824527","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@digi4care/shai-scan","version":"0.1.1","description":"Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like Mini Shai-Hulud (CVE-2026-45321).","type":"module","bin":{"shai-scan":"dist/cli.js"},"scripts":{"scan":"bun run src/cli.ts","build":"tsc -p tsconfig.build.json","check":"biome check src/","check:fix":"biome check --fix src/","release":"bumpp && npm publish"},"keywords":["security","supply-chain","npm","scanner","malware","shai-hulud","CVE-2026-45321"],"author":{"name":"Chris Engelhard"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/digi4care/shai-scan.git"},"bugs":{"url":"https://github.com/digi4care/shai-scan/issues"},"homepage":"https://github.com/digi4care/shai-scan#readme","engines":{"node":">=22.0.0"},"packageManager":"pnpm@10.11.0","devDependencies":{"@biomejs/biome":"^2.0.0","@types/node":"^25.8.0","bumpp":"^10.1.0","typescript":"^5.8.0"},"_id":"@digi4care/shai-scan@0.1.1","gitHead":"224720e18959e408dd9158d9e47fecff31e28ae3","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-FpJjHSW2LViejhv+oNKl1y+UrVYsRupy7kcbW4KQeKiQ3oTsBBO4Y9x8Zym179h4MKQfqsRESD1bSdkagZ5hHg==","shasum":"9252e57b86a127b90ccca008b84a2bc788eaba76","tarball":"https://registry.npmjs.org/@digi4care/shai-scan/-/shai-scan-0.1.1.tgz","fileCount":8,"unpackedSize":64650,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@digi4care%2fshai-scan@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEkFKM+bIjV/4zQp0XGMEWxUG8oA+VBS/BnRV1bWGp/VAiEAipqectuhow92ivNyV5VxXbsa1eCAS5PtGd6wC+JrJNQ="}]},"_npmUser":{"name":"digi4care","email":"c.engelhard@digi4care.nl"},"directories":{},"maintainers":[{"name":"digi4care","email":"c.engelhard@digi4care.nl"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/shai-scan_0.1.1_1778937353480_0.9450562683455488"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-16T12:59:00.627Z","modified":"2026-05-16T13:15:53.939Z","0.1.0":"2026-05-16T12:59:00.869Z","0.1.1":"2026-05-16T13:15:53.621Z"},"bugs":{"url":"https://github.com/digi4care/shai-scan/issues"},"author":{"name":"Chris Engelhard"},"license":"MIT","homepage":"https://github.com/digi4care/shai-scan#readme","keywords":["security","supply-chain","npm","scanner","malware","shai-hulud","CVE-2026-45321"],"repository":{"type":"git","url":"git+https://github.com/digi4care/shai-scan.git"},"description":"Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like Mini Shai-Hulud (CVE-2026-45321).","maintainers":[{"name":"digi4care","email":"c.engelhard@digi4care.nl"}],"readme":"# shai-scan\n\n> Zero-dependency CLI scanner for npm and PyPI supply chain compromises.\n\n[![npm version](https://img.shields.io/npm/v/@digi4care/shai-scan)](https://www.npmjs.com/package/@digi4care/shai-scan)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n[![Node.js](https://img.shields.io/badge/node-%3E%3D22-brightgreen)](https://nodejs.org/)\n\n## Why?\n\nOn May 11, 2026, a self-propagating supply chain worm dubbed **Mini Shai-Hulud** (CVE-2026-45321, GHSA-g7cv-rxg3-hmpx) compromised the npm ecosystem. Attributed to **TeamPCP** (aka DeadCatx3, PCPcat, ShellForce, CipherForce), the malware hijacked GitHub Actions OIDC tokens to publish malicious packages with valid SLSA Build Level 3 provenance. It stole credentials from CI/CD pipelines, cloud providers, and cryptocurrency wallets, and installed persistence hooks in Claude Code and VS Code. A built-in dead-man switch threatened to wipe the user's home directory if npm tokens were revoked.\n\nAffected packages included TanStack router and start packages, Mistral AI SDKs, OpenSearch client, UiPath tooling, and dozens of others. Because supply chain attacks move fast, organizations need a lightweight, trustworthy scanner they can run anywhere without adding new dependencies to their own attack surface.\n\n## Features\n\n- **Lockfile scanning** — Detects compromised npm and PyPI packages in `package-lock.json`, `pnpm-lock.yaml`, `yarn.lock`, `bun.lock`, `bun.lockb`, `poetry.lock`, `Pipfile.lock`, and `requirements.txt`\n- **System IOC checks** — Scans running processes, filesystem artifacts, network connections, and known persistence paths for indicators of compromise\n- **Zero runtime dependencies** — Uses only Node.js/Bun built-ins (`fs`, `path`, `child_process`, `os`). The scanner does not increase your supply chain risk\n- **Multiple output formats** — Human-readable text, machine-readable JSON, and SARIF for GitHub Code Scanning\n- **CI/CD native** — Exit codes designed for automation (`0` = clean, `1` = findings, `2` = error)\n- **Path-agnostic** — Accept any directory; defaults to the current working directory\n- **Campaign-based database** — New attack waves are added as discrete campaigns in `src/db.ts`; update the file and rerun\n\n## Install\n\nNo installation required. Run directly with your package runner of choice:\n\n```bash\n# npx\nnpx @digi4care/shai-scan\n\n# bunx\nbunx @digi4care/shai-scan\n\n# pnpm dlx\npnpm dlx @digi4care/shai-scan\n```\n\nGlobal install (optional):\n\n```bash\nnpm install -g @digi4care/shai-scan\n# or\npnpm add -g @digi4care/shai-scan\n```\n\nFrom source:\n\n```bash\ngit clone https://github.com/digi4care/shai-scan.git\ncd shai-scan\npnpm install\nbun run src/cli.ts --help   # Bun (recommended for development)\n# or build and run with Node.js:\npnpm run build && node dist/cli.js --help\n```\n\n## Usage\n\n### Scan the current project\n\n```bash\nnpx @digi4care/shai-scan\n```\n\n### Scan a specific path\n\n```bash\nnpx @digi4care/shai-scan ~/projects/my-app\n```\n\n### JSON output for automation\n\n```bash\nnpx @digi4care/shai-scan --json .\n```\n\n### SARIF output for GitHub Code Scanning\n\n```bash\nnpx @digi4care/shai-scan --sarif --sarif-file results.sarif .\n```\n\n### CI/CD exit codes\n\n```bash\n#!/bin/bash\nnpx @digi4care/shai-scan --severity high . || {\n  code=$?\n  if [ \"$code\" -eq 1 ]; then\n    echo \"Supply chain findings detected\"\n    exit 1\n  elif [ \"$code\" -eq 2 ]; then\n    echo \"Scanner error\"\n    exit 2\n  fi\n}\n```\n\n## CI/CD Integration\n\n### GitHub Actions (text output)\n\n```yaml\nname: Supply Chain Scan\non:\n  push:\n    branches: [main]\n  pull_request:\n    branches: [main]\n\njobs:\n  scan:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: pnpm/action-setup@v4\n      - uses: actions/setup-node@v4\n        with:\n          node-version: 22\n      - run: pnpm install --frozen-lockfile\n      - run: npx @digi4care/shai-scan --severity high .\n```\n\n### GitHub Actions (SARIF upload)\n\n```yaml\nname: Supply Chain Scan SARIF\non:\n  push:\n    branches: [main]\n  pull_request:\n    branches: [main]\n  schedule:\n    - cron: '0 6 * * 1'\n\njobs:\n  scan:\n    runs-on: ubuntu-latest\n    permissions:\n      security-events: write\n    steps:\n      - uses: actions/checkout@v4\n      - uses: pnpm/action-setup@v4\n      - uses: actions/setup-node@v4\n        with:\n          node-version: 22\n      - run: pnpm install --frozen-lockfile\n      - run: npx @digi4care/shai-scan --sarif --sarif-file results.sarif .\n      - uses: github/codeql-action/upload-sarif@v3\n        with:\n          sarif_file: results.sarif\n```\n\n## Output Formats\n\n| Format | Flag | Description |\n|--------|------|-------------|\n| Text   | (default) | Human-readable table of findings with severity, package name, version, and campaign details |\n| JSON   | `--json` | Structured JSON array of findings, suitable for ingestion into SIEMs or custom dashboards |\n| SARIF  | `--sarif` | OASIS SARIF 2.1.0 format for upload to GitHub Code Scanning, GitLab Secure, or other SARIF consumers |\n\nExample JSON excerpt:\n\n```json\n[\n  {\n    \"package\": \"@tanstack/react-router\",\n    \"version\": \"1.169.5\",\n    \"ecosystem\": \"npm\",\n    \"severity\": \"critical\",\n    \"campaign\": \"mini-shai-hulud-wave4\",\n    \"cve\": \"CVE-2026-45321\",\n    \"reference\": \"https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx\"\n  }\n]\n```\n\n## Exit Codes\n\n| Code | Meaning |\n|------|---------|\n| 0    | No compromised packages or IOCs detected |\n| 1    | One or more findings detected |\n| 2    | Runtime error (invalid path, unreadable lockfile, etc.) |\n\n## Adding New Campaigns\n\nWhen a new supply chain attack is discovered, update `src/db.ts`:\n\n1. Add a new `CompromisedVersion[]` array with the affected packages and versions\n2. Append a new `Campaign` object to the `CAMPAIGNS` array, including CVE/GHSA identifiers, severity, description, reference URLs, and IOC indicators\n3. The `buildLookup()` function automatically rebuilds the lookup map on the next run\n\nNo rebuild step is required when using Bun. Changes to `src/db.ts` take effect immediately with `bun run src/cli.ts`. For the npm package, run `pnpm run build` after editing.\n\n## Security Considerations\n\n- **Zero runtime dependencies**: The scanner uses only Node.js/Bun built-in modules. It does not download or execute third-party code at runtime, eliminating the risk that the scanner itself becomes a compromise vector.\n- **pnpm as package manager**: pnpm uses strict lockfiles, does not execute lifecycle scripts by default, and supports content-addressable storage. These properties reduce the attack surface compared to other package managers.\n- **Recommended `.npmrc` settings**: For maximum protection when installing packages, add the following to your project or global `.npmrc`:\n\n  ```ini\n  ignore-scripts=true\n  engine-strict=true\n  ```\n\n- **No network calls**: `shai-scan` does not phone home, download signatures, or require an API key. All campaign data is shipped with the package.\n\n## Affected Packages (Current Campaign)\n\nThe following packages and versions are known to be compromised in **CVE-2026-45321** (Mini Shai-Hulud Wave 4). This is a representative subset; the full list is maintained in `src/db.ts`.\n\n| Package | Ecosystem | Compromised Versions |\n|---------|-----------|---------------------|\n| `@tanstack/react-router` | npm | 1.169.5, 1.169.8 |\n| `@tanstack/vue-router` | npm | 1.169.5, 1.169.8 |\n| `@tanstack/solid-router` | npm | 1.169.5, 1.169.8 |\n| `@tanstack/router-core` | npm | 1.169.5, 1.169.8 |\n| `@tanstack/react-start` | npm | 1.167.68, 1.167.71 |\n| `@mistralai/mistralai` | npm | 2.2.2, 2.2.3, 2.2.4 |\n| `@mistralai/mistralai-azure` | npm | 1.7.2, 1.7.3 |\n| `mistralai` | pypi | 2.4.6 |\n| `@opensearch-project/opensearch` | npm | 3.5.3, 3.6.2, 3.7.0, 3.8.0 |\n| `@uipath/robot` | npm | 1.3.4 |\n| `@squawk/airways` | npm | 0.4.2, 0.4.3, 0.4.5 |\n| `@draftauth/core` | npm | 0.13.1, 0.13.2 |\n| `@tallyui/core` | npm | 0.2.1, 0.2.2, 0.2.3 |\n| `safe-action` | npm | 0.8.3, 0.8.4 |\n| `cmux-agent-mcp` | npm | 0.1.3 - 0.1.8 |\n| `nextmove-mcp` | npm | 0.1.3, 0.1.4, 0.1.5, 0.1.7 |\n| `ts-dna` | npm | 3.0.1, 3.0.2, 3.0.4 |\n| `cross-stitch` | npm | 1.1.3, 1.1.4, 1.1.6 |\n| `git-git-git` | npm | 1.0.8 - 1.0.12 |\n| `git-branch-selector` | npm | 1.3.3 - 1.3.7 |\n| `agentwork-cli` | npm | 0.1.4, 0.1.5 |\n| `wot-api` | npm | 0.8.1, 0.8.2, 0.8.4 |\n| `ml-toolkit-ts` | npm | 1.0.4, 1.0.5 |\n| `@beproduct/nestjs-auth` | npm | 0.1.2 - 0.1.19 |\n| `@dirigible-ai/sdk` | npm | 0.6.2, 0.6.3 |\n| `@taskflow-corp/cli` | npm | 0.1.24 - 0.1.29 |\n| `@tolka/cli` | npm | 1.0.2, 1.0.3, 1.0.4, 1.0.6 |\n| `@supersurkhet/cli` | npm | 0.0.2 - 0.0.7 |\n| `guardrails-ai` | pypi | 0.10.1 |\n\n## License\n\nMIT. See [LICENSE](LICENSE) for details.\n\n## Disclaimer\n\n`shai-scan` is a detection aid, not a substitute for comprehensive security audits, dependency review, or threat intelligence platforms. It identifies known compromised versions based on the shipped database; novel or zero-day supply chain attacks may not be detected until a campaign is added. Always practice defense in depth: audit dependencies, pin versions, verify provenance, and monitor CI/CD pipelines.\n","readmeFilename":"README.md"}