Just finished landing Exit Code support. So now if more scanners are made or one of the projects gets more features you can quickly switch to whichever makes the most sense for your use case!

I literally lost a ton of sleep on this volunteer incident response work so I'm going to go touch grass for a bit.

More hacks later tonight, still got some loose ends gnawing at me lol.

https://github.com/datapartyjs/walk-without-rhythm?tab=readme-ov-file#how-to-use

#nodejs #npm #javascript #Sha1Hulud #WalkWithoutRhythm #Sha1HuludScanner #cybersecurity

GitHub - datapartyjs/walk-without-rhythm: A tool to check your repos for signs of NPM supply chain attack using BASH

A tool to check your repos for signs of NPM supply chain attack using BASH - datapartyjs/walk-without-rhythm

GitHub

The fork of the CrowdStrike scanner introduced me to a really good idea, I should support the same exit code design so that our tools can work in tandem.

Maybe we detect different things or maybe one vs the other works in your environment.

So I made an issue to track this support:

https://github.com/datapartyjs/walk-without-rhythm/issues/18

#CrowdStrike #Sha1HuludScanner #WalkWithoutRhythm #cybersecurity #npm #nodejs

FEAT | Support CI/CD via exit codes · Issue #18 · datapartyjs/walk-without-rhythm

Another scanner introduced exit codes, thats a really good idea! We should adopt the same exit codes and meanings so our tools can easily be used interchangeably or in tandem. https://github.com/Ti...

GitHub

I located a second tool for detecting Sha1-Hulud infections. Haven't looked at the details of how it works.

Some notes:

This one appears to have been released by CrowdStrike and was paywalled. Someone decided to modify and release it publicly so license is unknown.

But awesome to see I'm in the big leagues with CrowdStrike and I maybe the first clean open source release of a tool for this.

https://github.com/TimothyMeadows/sha1hulud-scanner

#Sha1Hulud #Sha1HuludScanner #NPM #nodejs #cybersecurity #opensource

GitHub - TimothyMeadows/sha1hulud-scanner: Scanner for detecting malicious npm packages from Sha1-Hulud: The Second Coming supply chain attack. Protects against credential theft and destructive home directory deletion.

Scanner for detecting malicious npm packages from Sha1-Hulud: The Second Coming supply chain attack. Protects against credential theft and destructive home directory deletion. - TimothyMeadows/sha1...

GitHub