
كشف CVE-2026-45321 Mini Shai-Hulud اختراق سلسلة التوريد — يفحص 170 حزمة npm و2 حزم PyPI مسمومة عبر TanStack وMistral AI وUiPath وOpenSearch وGuardrails AI
ماسح Bash سريع بدون أي تبعيات للكشف عن ما إذا كان جهازك متأثرًا بهجوم سلسلة التوريد CVE-2026-45321 "Mini Shai-Hulud".
في 11 مايو 2026، تم تسميم أكثر من 170 حزمة npm وحزمتي PyPI في وقت واحد عبر TanStack وMistral AI وUiPath وOpenSearch وGuardrails AI. تسرق الحمولة الخبيثة بيانات اعتماد AWS ورموز GitHub ورموز npm وأسرار Vault ومفاتيح SSH — وتتضمن دودة ذاتية الانتشار تنتشر عبر خطوط أنابيب CI/CD.
curl -fsSL https://raw.githubusercontent.com/qi-scape/scan-shai-hulud/main/scan-shai-hulud.sh | bash
أو استنسخ ونفّذ:
git clone https://github.com/qi-scape/scan-shai-hulud.git
cd scan-shai-hulud
chmod +x scan-shai-hulud.sh
./scan-shai-hulud.sh
# Scan current directory + system-wide persistence checks
./scan-shai-hulud.sh
# Scan a specific project
./scan-shai-hulud.sh ~/my-project
# Deep scan across entire home directory
./scan-shai-hulud.sh --full
ينفّذ الماسح 8 خطوات:
170 حزمة npm موزعة على 15 نطاقًا:
react-router, vue-router, solid-router, router-core, إلخ.)mistralai, mistralai-azure, mistralai-gcpopensearchagentwork-cli, cmux-agent-mcp, cross-stitch, , , , , , , حزمتان من PyPI:
mistralai==2.4.6guardrails-ai==0.10.1إذا أبلغ الماسح عن نتائج حرجة:
ghp_*, gho_*, ghs_*)، ورموز npm، ورموز Vault، ومفاتيح SSH، ورموز حسابات الخدمة في Kubernetesnpm cache clean --force && rm -rf node_modules && npm installlaunchctl unload ~/Library/LaunchAgents/com.user.gh-token-monitor.plist2026-05-11T19:20Znpm access ls-packagesfind, grep, shasum)mdfind (Spotlight في macOS، يُستخدم للبحث الأسرع في الملفات)npm, pip (لفحص الحزم/الرموز)git (لفحص المستودعات)lsof (لفحص اتصالات الشبكة)MIT
| الخطوة | الوصف |
|---|
| الثبات | LaunchAgent في macOS (الملف + حالة التحميل عبر launchctl), خدمة systemd في Linux, سكربت مفتاح الرجل الميت, مواضع إسقاط الحمولة في .claude/ و .vscode/, سير عمل GitHub Actions المحقونة, مُسقطات /tmp |
| الملفات الخبيثة | router_init.js, tanstack_runner.js, router_runtime.js, gh-token-monitor.sh, transformers.pyz — تم التحقق منها مقابل 3 هاشات SHA-256 معروفة |
| مؤشرات C2 | يفحص ملفات الإعداد (.npmrc, .bashrc, .zshrc, .env) ومصدر المشروع بحثًا عن 6 نطاقات C2 وعلامات الحملة |
| حزم npm | جميع أشجار node_modules, الجذر العام لـ npm, ملفات القفل (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock), ذاكرة التخزين المؤقت لـ npm — مع مطابقة دقيقة لكل حزمة (42 حزمة @tanstack router محددة، وليس النطاق بأكمله) |
| حزم PyPI | pip show عبر جميع بيئات Python/conda + requirements.txt, pyproject.toml, Pipfile, poetry.lock |
| مستودعات Git | هاش الالتزام الخبيث في السجل, فروع الإسقاط الميت dependabout/*/setup-formatter, مؤلف التزام الإسقاط الميت, codeql_analysis.yml المحقون |
| سجل الصدفة والبيئة | سجل Bash/Zsh/Fish لآثار تنفيذ الحمولة, ملفات RC الخاصة بالصدفة للحقن, متغيرات البيئة لنطاقات C2 |
| الشبكة والرموز | الاتصالات النشطة بـ C2 عبر lsof, /etc/hosts, ~/.ssh/known_hosts, قائمة رموز npm |
git-branch-selectorgit-git-gitml-toolkit-tsnextmove-mcpsafe-actionts-dnawot-api| المؤشر | القيمة |
|---|
| الاستخراج الأساسي | filev2.getsession.org |
| بذور الجلسات | seed{1,2,3}.getsession.org |
| C2 ثانوي | api.masscan.cloud, git-tanstack.com |
| منطقة تجهيز الحمولة | litter.catbox.moe/h8nc9u.js, litter.catbox.moe/7rrc6l.mjs |
| الالتزام الخبيث | 79ac49eedf774dd4b0cfa308722bc463cfe5885c |