Shai Hulud 2.0 Detector
Check if your project is affected by the Shai Hulud 2.0 supply chain attack
What is Shai Hulud 2.0?
On November 24, researchers discovered a second Shai Hulud supply chain attack that compromised over 25,000 repositories across ~350 npm packages, including popular packages from Zapier, PostHog, and Postman. Malicious code exfiltrates developer and CI/CD secrets, cloud provider credentials, and can escalate privileges in Docker environments. Learn more
Upload your package-lock.json or package.json file to check if your project uses any affected packages.
📦
Click to upload or drag and drop
package-lock.json or package.json
All analysis is performed client-side in your browser. No data is uploaded or stored on our servers.
Note: this tool is not necessarily comprehensive. The abscense of a package in this list does not necessarily mean your project is not affected.
Note: this tool is not necessarily comprehensive. The abscense of a package in this list does not necessarily mean your project is not affected.