Skip to content

Instantly share code, notes, and snippets.

View sbimochan's full-sized avatar
🎩
Sherlock Holmes mode

Bimochan Shrestha sbimochan

🎩
Sherlock Holmes mode
View GitHub Profile
#!/usr/bin/env bash
# ─────────────────────────────────────────────────────────────────────────────
# detect-mini-shai-hulud.sh
#
# Scans every git project under the CWD across ALL branches (local + already
# fetched remote-tracking branches) for npm packages compromised in the
# "Mini Shai-Hulud" supply-chain attack (npm ecosystem, 2026).
#
# For every watched package found in any lockfile on any branch, the script
# reports the project, branch, package, version, and whether that version is