Skip to content
#

credential-theft

Here are 18 public repositories matching this topic...

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Jun 28, 2026
  • TypeScript
thumper

Thumper is an open-source tripwire for the Shai-Hulud npm worm. Plant fake-but-realistic credentials where the worm scans - the instant one is read, you know the box might be breached. Free and built in the open by Jesta.

  • Updated Jun 28, 2026
  • Python

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger retry storms, bypass TLS validation, and request unauthorized entitlements. Confirmed on iOS 18.6.2 with potential iCloud-based propagation.

  • Updated Mar 20, 2026

Runtime dependency-behavior monitor for Node.js. Two engines: in-process telemetry + an out-of-process (strace) trust boundary that sees native egress & persistence. Defense-in-depth for npm supply-chain attacks — SARIF, GitHub Action, zero deps.

  • Updated Jun 28, 2026
  • JavaScript

Forensic dataset + live dashboard for the 2026-04-29 'A Mini Shai-Hulud has Appeared' npm supply-chain worm by TeamPCP. 1,117 dropbox repos, 22 compromised accounts, 47 IOCs across 14 kinds. Trojaned: @cap-js, mbt, @bitwarden/cli. C2 attribution to AS209101 IP Vendetta Inc. JSONL data · kinetic dashboard · CC-BY-4.0.

  • Updated Apr 29, 2026
  • Shell

AD (Active Directory) Service Account Manager is an enterprise-grade PowerShell framework that codifies identity lifecycle management and eliminates identity debt within Active Directory. It transitions organizations away from fragmented, manual service account management into a structured, audited, and automated governance model.

  • Updated Mar 2, 2026
  • PowerShell

Threat-intel teardown + keyless live tracker of a multi-brand marketplace phishing-as-a-service (PhaaS) operation (Classiscam/Telekopye class) impersonating OLX, Subito, Kleinanzeigen & ~120 brands to steal card data + 3-D Secure/OTP. IOCs, kit analysis, detection signatures.

  • Updated Jun 29, 2026
  • HTML

Improve this page

Add a description, image, and links to the credential-theft topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the credential-theft topic, visit your repo's landing page and select "manage topics."

Learn more