{"_id":"sha1-hulud-scanner","_rev":"2-95763942cf6e956b9b2597927b261fcc","name":"sha1-hulud-scanner","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"sha1-hulud-scanner","version":"1.0.0","keywords":["security","npm","supply-chain","sha1-hulud","shai-hulud","malware","scanner","vulnerability","audit","koi"],"author":{"name":"developerjhp"},"license":"MIT","_id":"sha1-hulud-scanner@1.0.0","maintainers":[{"name":"developerjhp","email":"developerjhp@gmail.com"}],"homepage":"https://github.com/developerjhp/sha1-hulud-scanner#readme","bugs":{"url":"https://github.com/developerjhp/sha1-hulud-scanner/issues"},"bin":{"sha1-hulud-scanner":"scan.js"},"dist":{"shasum":"b9c8484993fe80a8189271ba0977080d90a4d9dd","tarball":"https://registry.npmjs.org/sha1-hulud-scanner/-/sha1-hulud-scanner-1.0.0.tgz","fileCount":4,"integrity":"sha512-Ue4fkkec86dlA9GyoQEZu+1zCsT3FfqZxyyVd43i5ql7nzMtGhijTIMaO3ymFDrdEwKMtfWKMeynXWtByX4kcw==","signatures":[{"sig":"MEMCH1eDiuOTuec5z5J30ddp9XuCxTQUvUPkEdBd5x9Uor0CIBunjKQO74H0flrEXM2R49Y4+t2CTvCuDCrRqVOlUMbI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45801},"main":"scan.js","engines":{"node":">=14.0.0"},"gitHead":"d16cba61c0cbd8fde4916e2f685f79c06188bebe","scripts":{"scan":"node scan.js","scan:json":"node scan.js --json","scan:verbose":"node scan.js --verbose"},"_npmUser":{"name":"developerjhp","email":"developerjhp@gmail.com"},"repository":{"url":"git+https://github.com/developerjhp/sha1-hulud-scanner.git","type":"git"},"_npmVersion":"11.5.2","description":"Sha1-Hulud 2.0 npm supply chain attack scanner - Real-time detection using Koi.ai data","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/sha1-hulud-scanner_1.0.0_1764047110756_0.885067677948737","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"sha1-hulud-scanner","version":"1.0.1","description":"Sha1-Hulud 2.0 npm supply chain attack scanner - Real-time detection using Koi.ai data","main":"scan.js","bin":{"sha1-hulud-scanner":"scan.js"},"scripts":{"scan":"node scan.js","scan:verbose":"node scan.js --verbose","scan:json":"node scan.js --json"},"keywords":["security","npm","supply-chain","sha1-hulud","shai-hulud","malware","scanner","vulnerability","audit","koi"],"author":{"name":"developerjhp"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/developerjhp/sha1-hulud-scanner.git"},"bugs":{"url":"https://github.com/developerjhp/sha1-hulud-scanner/issues"},"homepage":"https://github.com/developerjhp/sha1-hulud-scanner#readme","engines":{"node":">=14.0.0"},"_id":"sha1-hulud-scanner@1.0.1","gitHead":"d16cba61c0cbd8fde4916e2f685f79c06188bebe","_nodeVersion":"22.14.0","_npmVersion":"11.5.2","dist":{"integrity":"sha512-wjVzv6odujmiLqClyJpCGFRqqkM3wvm9E5WkvXQ60X+Ex+3br4FsKqDfPKwA9bJSwql7kI38vZ6ROp1HQQO4aQ==","shasum":"e188c1211a65ea596cc784638dedcefb1af7a1d7","tarball":"https://registry.npmjs.org/sha1-hulud-scanner/-/sha1-hulud-scanner-1.0.1.tgz","fileCount":4,"unpackedSize":46193,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDlwlb/63NiBjgnoYqqUkGBO3FM6h/viVTsY+yP2VCL9wIhAKAPtK222d4v+RHXD8bUOmUp3D1jsDC8N0ghOYbrd9u7"}]},"_npmUser":{"name":"developerjhp","email":"developerjhp@gmail.com"},"directories":{},"maintainers":[{"name":"developerjhp","email":"developerjhp@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sha1-hulud-scanner_1.0.1_1764047178506_0.7344346086103504"},"_hasShrinkwrap":false}},"time":{"created":"2025-11-25T05:05:10.755Z","modified":"2025-11-25T05:06:18.889Z","1.0.0":"2025-11-25T05:05:10.945Z","1.0.1":"2025-11-25T05:06:18.683Z"},"bugs":{"url":"https://github.com/developerjhp/sha1-hulud-scanner/issues"},"author":{"name":"developerjhp"},"license":"MIT","homepage":"https://github.com/developerjhp/sha1-hulud-scanner#readme","keywords":["security","npm","supply-chain","sha1-hulud","shai-hulud","malware","scanner","vulnerability","audit","koi"],"repository":{"type":"git","url":"git+https://github.com/developerjhp/sha1-hulud-scanner.git"},"description":"Sha1-Hulud 2.0 npm supply chain attack scanner - Real-time detection using Koi.ai data","maintainers":[{"name":"developerjhp","email":"developerjhp@gmail.com"}],"readme":"# Sha1-Hulud 2.0 Supply Chain Attack Scanner\n\nA security scanner that detects npm packages compromised by the **Sha1-Hulud 2.0** supply chain attack. Downloads real-time infected package lists from [Koi.ai](https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised) and scans your project.\n\n## About the Attack\n\nSha1-Hulud 2.0 is an ongoing npm supply chain attack that has compromised **800+ packages** affecting **25,000+ repositories**. The malware:\n\n- Injects malicious `preinstall` scripts (`setup_bun.js`, `bun_environment.js`)\n- Harvests credentials (npm tokens, GitHub PATs, SSH keys, cloud credentials)\n- Exfiltrates secrets to attacker-controlled GitHub repositories\n- Creates persistent backdoors in GitHub Actions workflows\n- Can act as a wiper, deleting the user's home directory as a fallback\n\n**Affected organizations include**: PostHog, ENS Domains, Zapier, and many more.\n\n## Features\n\n- **Real-time Data**: Downloads latest compromised package list from Koi.ai\n- **Multiple Lock File Support**: package-lock.json, yarn.lock, pnpm-lock.yaml\n- **Direct node_modules Scan**: Verifies actual installed package versions\n- **IOC Detection**: Scans for malicious files and suspicious patterns\n- **GitHub Actions Audit**: Checks for compromised workflows and branches\n- **JSON Output**: Machine-readable output for CI/CD integration\n- **Caching**: 1-hour cache to reduce API calls\n\n## Installation\n\n```bash\n# Using npx (no install needed)\nnpx sha1-hulud-scanner\n\n# Or install globally\nnpm install -g sha1-hulud-scanner\n\n# Or clone repository\ngit clone https://github.com/developerjhp/sha1-hulud-scanner.git\ncd sha1-hulud-scanner\n```\n\n## Usage\n\n### Node.js Version\n\n```bash\n# Scan current directory\nnode scan.js\n\n# Scan specific project\nnode scan.js /path/to/your/project\n\n# Verbose output\nnode scan.js -v\n\n# JSON output (for CI/CD)\nnode scan.js --json\n\n# Force fresh download (ignore cache)\nnode scan.js --no-cache\n\n# Generate JSON report\nnode scan.js --json > security-report.json\n```\n\n### Bash Version\n\n```bash\n# Make executable\nchmod +x scan.sh\n\n# Scan current directory\n./scan.sh\n\n# Scan specific project\n./scan.sh /path/to/your/project\n```\n\n## Output Examples\n\n### Clean Project\n\n```\n╔═══════════════════════════════════════════════════════════════╗\n║        🐛 Sha1-Hulud 2.0 Supply Chain Attack Scanner         ║\n║                                                               ║\n║  Data Source: Koi.ai Live Updates                            ║\n╚═══════════════════════════════════════════════════════════════╝\n\n[ℹ] Project path: /Users/dev/my-project\n[ℹ] Downloaded compromised package list (847 entries)\n\n[1/4] Package Lock File Scan\n[ℹ] Scanning package-lock.json...\n\n[2/4] Direct node_modules Scan\n[ℹ] Direct node_modules scan...\n\n[3/4] IOC File Scan\n[ℹ] Scanning for IOC files...\n\n[4/4] GitHub Actions Scan\n[ℹ] Scanning GitHub Actions...\n\n═══════════════════════════════════════════════════════════════\n                         SCAN REPORT\n═══════════════════════════════════════════════════════════════\n\nPackages checked:  847\nInfected packages: 0\nWarnings:          0\n\n✅ No infection detected!\n```\n\n### Infected Project\n\n```\n═══════════════════════════════════════════════════════════════\n                         SCAN REPORT\n═══════════════════════════════════════════════════════════════\n\nPackages checked:  847\nInfected packages: 2\nWarnings:          1\n\n🚨 INFECTION DETECTED! Immediate action required!\n\nInfected packages:\n  • @posthog/siphash@1.2.3\n  • @ensdomains/ensjs@4.0.1\n\nRecommended actions:\n  1. Remove infected packages immediately or rollback to safe versions\n  2. Rotate npm tokens, GitHub PATs, SSH keys immediately\n  3. Rotate AWS/GCP/Azure cloud credentials\n  4. Review .github/workflows/ directory manually\n  5. Check git log for suspicious commits\n\nReference: https://www.koi.ai/incident/live-updates-sha1-hulud\n```\n\n## What It Scans\n\n### 1. Package Lock Files\n- Compares your `package-lock.json`, `yarn.lock`, or `pnpm-lock.yaml` against known compromised packages\n\n### 2. node_modules Directory\n- Directly reads `package.json` files to verify installed versions\n\n### 3. IOC Files\nSearches for known malicious files:\n- `setup_bun.js`\n- `bun_environment.js`\n- `cloud.json`\n- `contents.json`\n- `environment.json`\n- `truffleSecrets.json`\n\n### 4. Suspicious Preinstall Scripts\nFlags preinstall scripts containing:\n- `bun` references\n- `curl` / `wget` commands\n- `eval()` / `exec()` calls\n- Shell script execution\n\n### 5. Malicious Domain References\nSearches for references to:\n- `packages.storeartifact.com`\n- `hulud` related strings\n\n### 6. GitHub Actions\n- Workflow files with `hulud` in filename\n- Suspicious content in workflow YAML files\n- Git branches containing `hulud`\n\n## CI/CD Integration\n\n### GitHub Actions\n\n```yaml\nname: Security Scan\n\non: [push, pull_request]\n\njobs:\n  sha1-hulud-scan:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n\n      - name: Setup Node.js\n        uses: actions/setup-node@v4\n        with:\n          node-version: '20'\n\n      - name: Download Scanner\n        run: |\n          curl -sL https://raw.githubusercontent.com/developerjhp/sha1-hulud-scanner/main/scan.js -o scan.js\n\n      - name: Run Sha1-Hulud Scanner\n        run: node scan.js --json > scan-results.json\n\n      - name: Check Results\n        run: |\n          if [ $(node -e \"console.log(require('./scan-results.json').infected.length)\") -gt 0 ]; then\n            echo \"🚨 Infected packages detected!\"\n            cat scan-results.json\n            exit 1\n          fi\n```\n\n### Pre-commit Hook\n\n```bash\n#!/bin/sh\n# .git/hooks/pre-commit\n\nnode /path/to/sha1-hulud-scanner/scan.js\nif [ $? -ne 0 ]; then\n    echo \"🚨 Sha1-Hulud infection detected! Commit blocked.\"\n    exit 1\nfi\n```\n\n## JSON Output Schema\n\n```json\n{\n  \"scanTime\": \"2025-11-25T10:30:00.000Z\",\n  \"projectPath\": \"/path/to/project\",\n  \"totalPackagesChecked\": 847,\n  \"infected\": [\n    \"@package/name@1.0.0\"\n  ],\n  \"warnings\": [\n    \"Suspicious preinstall: some-package - \\\"node setup.js\\\"\"\n  ],\n  \"iocFindings\": [\n    {\n      \"type\": \"malicious_file\",\n      \"path\": \"/path/to/setup_bun.js\"\n    }\n  ],\n  \"githubActionsFindings\": [\n    {\n      \"type\": \"suspicious_workflow_content\",\n      \"path\": \".github/workflows/build.yml\"\n    }\n  ],\n  \"clean\": false\n}\n```\n\n## Exit Codes\n\n| Code | Meaning |\n|------|---------|\n| 0 | No infection detected |\n| 1 | Infection detected or scan error |\n\n## Remediation Steps\n\nIf infection is detected:\n\n1. **Isolate**: Do not run `npm install` or any npm scripts\n2. **Identify**: Note all infected package versions from the report\n3. **Remove/Rollback**:\n   ```bash\n   # Remove infected package\n   npm uninstall @infected/package\n\n   # Or rollback to safe version\n   npm install @infected/package@safe-version\n   ```\n4. **Rotate Credentials**:\n   - npm tokens: `npm token revoke` + create new\n   - GitHub PATs: Settings → Developer settings → Regenerate\n   - SSH keys: Generate new keypairs\n   - AWS/GCP/Azure: Rotate all access keys and secrets\n5. **Audit GitHub Actions**:\n   - Review `.github/workflows/` for suspicious files\n   - Check for unexpected branches\n   - Review recent commits\n6. **Scan CI/CD Environments**: Check for persistence mechanisms\n\n## Data Source\n\nThis scanner uses the live compromised package list maintained by [Koi Security](https://www.koi.ai/):\n\n- **URL**: https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised\n- **CSV**: Auto-downloaded and cached for 1 hour\n- **Updates**: Koi.ai continuously updates the list as new compromised packages are discovered\n\n## References\n\n- [Koi.ai - Live Updates: Sha1-Hulud](https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised)\n- [Wiz Blog - Sha1-Hulud 2.0](https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack)\n- [Snyk - SHA1-Hulud Incident](https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/)\n- [CISA Alert](https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem)\n\n## License\n\nMIT\n\n## Contributing\n\nIssues and PRs welcome! Please ensure any contributions maintain zero external dependencies.\n","readmeFilename":"README.md"}