Shai Hulud 2.0 Detector

Check if your project is affected by the Shai Hulud 2.0 supply chain attack

What is Shai Hulud 2.0?

On November 24, researchers discovered a second Shai Hulud supply chain attack that compromised over 25,000 repositories across ~350 npm packages, including popular packages from Zapier, PostHog, and Postman. Malicious code exfiltrates developer and CI/CD secrets, cloud provider credentials, and can escalate privileges in Docker environments. Learn more


Upload your package-lock.json or package.json file to check if your project uses any affected packages.


📦
Click to upload or drag and drop
package-lock.json or package.json
All analysis is performed client-side in your browser. No data is uploaded or stored on our servers.

Note: this tool is not necessarily comprehensive. The abscense of a package in this list does not necessarily mean your project is not affected.