Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/dhawaldesai/agentic-ioc-scanner
Indicator of Compromise (IOC) ManagementStatic AnalysisVulnerability ScannersCode AnalysisMalware AnalysisThreat IntelligenceSupply Chain SecurityPapers & ResearchLearning & EducationIncident ResponseCurated Resources
GitHubdhawaldesai/agentic-ioc-scanner

agentic-ioc-scanner

IOC scanner for agentic AI coding tools — detects Mini Shai-Hulud, Gemini CLI RCE, Cursor CVE-2026-26268, and DPRK PromptMink.

View Repository
114 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

agentic-ioc-scanner

IOC scanner for agentic AI coding tools — detects Mini Shai-Hulud, Gemini CLI RCE, Cursor CVE-2026-26268, and DPRK PromptMink.

A detection kit for compromise of agentic AI coding assistants (Claude Code, Gemini CLI, Cursor) and the dependencies they pull into your repos. Eleven checks across hook injection, RCE configs, malicious dependencies, git-hook backdoors, and CI workflow tampering. IOC list is externalised — adding new indicators requires no code changes.

Companion blog post: When the Tool Fights Back.

What's Included

1. IOC Scanner (scanner/ais.sh)

Eleven checks, each with an inline What: (purpose) and Fix: (remediation) printed under the section header so the report is self-explanatory. IOC list lives in scanner/iocs.txt (versioned; override with IOC_FILE=/path/to/iocs.txt).

§CheckThreat covered
1Claude Code SessionStart hook injection in any settings.json (jq-based, low-FP)Mini Shai-Hulud persistence
2Bun-runtime dropper signatures in setup.mjsMini Shai-Hulud install stage
3Obfuscated execution.js payloads — size plus obfuscation signal (single-line, base64, eval(atob(, child_process)Mini Shai-Hulud credential stealer
4Malware lock files in $TMPDIR (names sourced from IOC list)Mini Shai-Hulud sentinel
5package.json preinstall scripts referencing dropper filenamesGeneric supply-chain worm entry point
6AI-authored commits touching .github/workflows/ (email-allowlist filter)CI tampering by compromised AI-agent identity
7.gemini/ config files with shell-metachar patternsGemini CLI CVSS 10.0 RCE (pre-v0.39.1)
8Cursor AGENTS.md and .cursor/ configs referencing git hooks / bare reposCursor CVE-2026-26268
9Git post-checkout / post-merge / post-rewrite / pre-commit hooks containing fetch-and-execute primitives, plus core.hooksPath redirected outside the safe allowlistCVE-2026-26268 exec primitive + generic hook hijacking
10Globally-installed and local node_modules packages cross-referenced against the IOC listMini Shai-Hulud SAP CAP set, DPRK PromptMink, future bad packages
11Git remotes matching known worm exfiltration repo names (Shai-Hulud, A Mini Shai-Hulud has Appeared)Confirmed-compromise signal

Usage:

bash scanner/ais.sh
# Enter your project folder when prompted

# Custom IOC list:
IOC_FILE=./my-iocs.txt bash scanner/ais.sh

# Custom report path (default: ./agentic-ioc-scan-YYYYMMDD-HHMMSS.log):
REPORT_FILE=/var/log/agentic-scan.log bash scanner/ais.sh

Output

  • Findings stream to the terminal (colourised) and to a plain-text report file (agentic-ioc-scan-YYYYMMDD-HHMMSS.log by default, ANSI-stripped via tee → sed).
  • Severity tags: [CRITICAL] (act now), [WARNING] (likely malicious — verify), [REVIEW] (legitimate use possible — confirm), [OK] (clean).
  • File-content findings include the line number where the indicator was found (path:line form). Sections that surface line numbers: §1 hook, §2 Bun signature, §3 obfuscation signal, §5 preinstall key, §7 Gemini metachar, §8 AGENTS.md git-hook reference, §9 suspicious hook contents.
  • The §11 worm-remote finding additionally reports the offending .git/config line plus the matching remote URL, so you can jump straight to the entry that needs removing.
  • core.hooksPath redirection (§9) reports the absolute path to the repo's .git/config so the reassignment is auditable.
  • Worktree-aware: when a .git is a file (containing gitdir: …), the actual git directory is resolved before inspection.

Sample finding

[CRITICAL] Repo points to known worm exfil name
           Repo:   /home/dev/projects/myrepo
           Config: /home/dev/projects/myrepo/.git/config:9
           URL:    https://github.com/dhawaldesai/A-Mini-Shai-Hulud-has-Appeared

[CRITICAL] Malicious hook: /home/dev/projects/myrepo/.claude/settings.json:3
[CRITICAL] Suspicious git post-checkout hook: /home/dev/projects/myrepo/.git/hooks/post-checkout:2

Updating IOCs

Edit scanner/iocs.txt and bump the # version: header. Format is TYPE|VALUE|NOTES. Supported types:

TypeUsed byExample
FILENAME§5 preinstall patternsetup.mjs
LOCKFILE§4 lock-file scantmp.987654321.lock
NPM§10 global + local package scan@validate-sdk/v2
PYPI§10 (cross-checked when a PyPI scanner is added)lightning
HOOKSTRING§1 hook content match (currently inline-coded)SessionStart
REPONAME§11 git-remote matchA Mini Shai-Hulud has Appeared
EMAILSUBSTRINGreserved for future commit-author IOC matching—
CONFIGPATHreference list of agentic-tool config paths.claude/settings.json

No code change is required when new IOCs surface — the scanner reads them at startup and prints the loaded version in the banner.

Dependencies

Required: bash, find, grep, awk, sed, git. Optional: jq (preferred for §1 — falls back to grep heuristic if absent), npm (required for §10 global package check; section is skipped silently if unavailable).

2. Affected-Package Version Scanner (scanner/pkg_version_check.sh)

Companion to the IOC scanner. Reads a CSV of affected package,version pairs (e.g. the Mini Shai-Hulud IOC feed at ~/Downloads/Mini Shai-Hulud - Sheet1.csv — 633 npm package/version pairs) and checks whether they appear in:

  1. A user-supplied local project directory — scans package.json, package-lock.json, yarn.lock, pnpm-lock.yaml, and installed node_modules/<pkg>/package.json. PyPI manifests (requirements.txt, poetry.lock, Pipfile.lock) are also checked when the CSV contains unscoped names.
  2. The user's GitHub repos — via gh CLI: code search across lockfile types, then exact-version validation via the dependency-graph SBOM API (/repos/{owner}/{repo}/dependency-graph/sbom).

Severity model: exact pkg@version match in a lockfile, node_modules/, or SBOM → [CRITICAL]. Range specifier (^1.2.3, ~1.2.3, >=…) that could include the affected version → [REVIEW]. Package name match without version confirmation → [REVIEW]. Output streams to terminal and to ./shai-hulud-pkg-scan-YYYYMMDD-HHMMSS.log (ANSI-stripped), with a severity-breakdown summary at the end.

Usage:

# Interactive — prompts for project directory
bash scanner/pkg_version_check.sh

# Fully scripted (env-var overrides)
PROJECT_DIR=/path/to/project \
  IOC_CSV="$HOME/Downloads/Mini Shai-Hulud - Sheet1.csv" \
  REPORT_FILE=/var/log/pkg-scan.log \
  bash scanner/pkg_version_check.sh --skip-node-modules

CSV format: col1 = package name (scoped names like @scope/pkg supported), col2 = exact affected version. A header row is auto-detected and skipped. Override the path with IOC_CSV=….

Dependencies: bash, find, grep, awk, sed. Optional: jq (improves node_modules/<pkg>/package.json parsing accuracy), gh (required for the GitHub phase — phase is skipped with a clear message if absent or unauthenticated).

Known limitations:

  • GitHub code search misses lockfiles >384KB and only indexes default branches — the SBOM path is the authoritative check.
  • GitHub phase is rate-limit-bound (10 req/min authenticated); throttled at ~5 packages per 7s, so a full 633-row CSV takes ~22 minutes against GitHub. Run local scans first, GitHub phase separately.
  • Lockfile parsing is grep-based, not fully parsed — deeply nested or unusual formatting may produce false negatives. Highest-value follow-up is jq-based lockfile parsing.
  • SBOM API requires the repo's dependency graph to be enabled and indexed; repos without it fall back to [REVIEW].
Download Tool