shai-hulud-checker
v0.2.1
Published
Scan yarn/npm/pnpm lockfiles for compromised packages from the Shai-Hulud npm supply-chain attack.
Readme
Mini Shai Hulud Checker - 2026-05-19 attack wave
Usage
- Clone this repo
- Go to the root folder where you have all your repos
- Run
node shai-hulud-checker/cli.mjsand wait a bit
Previous attacks
List of compromised packages for previous waves are distributed with the checker:
2026-05-19.csv— the original @antv wave (317 packages)2026-08-04.csv— the keyv wave (443 packages)
Each CSV has two columns:
Package,Malicious Versions
@scope/name,"1.0.1, 1.0.2, 1.0.3"
some-pkg,2.3.4By default the checker uses the most recent wave. To check against a specific one, pass its date:
node shai-hulud-checker/cli.mjs --date 2026-05-19You can also point at an arbitrary CSV anywhere on disk with --list path/to/file.csv.
Reading the output
By default, the report includes two groups: HITS (an installed version matches
a compromised release) and PRESENCE (the package is on the list but at a
version that wasn't flagged). To report only actual compromises, pass
--hits-only:
node shai-hulud-checker/cli.mjs --hits-onlyWhat to do if I'm hit? 2026-05-19
- Read https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/ carefully
- Close and then clean up all IDEs and ADEs
- Clean up your OS as it is compromised too
- Clean up all your local Git repos
- Check on GitHub whether any local repo had commits made to propagate the infection
- Warn any contributors to any repos you have checked out on your machine
What to do if I'm hit? 2026-08-04
Read https://safedep.io/keyv-npm-supply-chain-compromise/ carefully. It contains remediation steps.
What to do if I'm using compromised packages but I'm not hit (I'm using older versions)?
Warn any contributors to these repos, as they might have updated local dependencies and might have gotten infected.
