Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
supply-chain-guard — Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT (2026-03-31) and Starlette BadHost CVE-2026-48710 (2026-05-22). | Kitploit
Tools/GitHubGitHub/eris-ths/supply-chain-guard
Indicator of Compromise (IOC) ManagementVulnerability ScannersScripting & AutomationMalware AnalysisDevSecOpsThreat IntelligenceSupply Chain SecurityLearning & EducationIncident Response
GitHuberis-ths/supply-chain-guard

supply-chain-guard

Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT (2026-03-31) and Starlette BadHost CVE-2026-48710 (2026-05-22).

3203 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Supply Chain Guard (SCG)

An incident-response toolkit for npm/yarn and Python (pip/poetry/uv) supply chain attacks — free, local, dependency-free.

SCG is not a scanning engine that competes with commercial tools on coverage. It is a Claude Code skill and standalone shell toolkit that does three things well: (1) gives you a fast, repeatable first response when a specific incident drops ("is my machine affected right now?"), (2) orchestrates existing OSS scanners (npm audit, osv-scanner, pip-audit) into one structured pass, and (3) documents hard-won design-hygiene lessons — especially for AI development environments — that generic scanners don't cover.

It was built and hardened during real incidents, including:

  • [email protected] RAT incident (2026-03-31) — npm maintainer account takeover (UNC1069/DPRK-APT) injecting a phantom dependency RAT
  • Starlette BadHost (CVE-2026-48710, 2026-05-22) — Python HTTP framework Host header path injection → SSRF/RCE, affecting FastAPI, vLLM, LiteLLM, and the broader AI agent ecosystem

What's new in v4 (2026-05-27)

  • Python supply chain scan — scripts/project-scan-py.sh with pip-audit / osv-scanner / CVE-flagged version detection
  • CVE-flagged version layer (L3-CVE) — track known vulnerable versions of legitimate packages with strict semver-spec evaluation (BadHost CVE-2026-48710 included out of the box)
  • Design hygiene guideline — stdio-first MCP transport, version pin discipline, GCP default compute SA editor hardening (see SKILL.md §D.7 DesignHygiene)
  • Guild-CLI Devil lense integration — invoke SCG as a Devil lense from guild-cli workflows (see "Guild-CLI Devil Integration" below)

Table of Contents

  • Why This Exists
  • How SCG Differs from Existing Tools
  • What SCG Is (and Isn't)
  • Architecture
  • Quick Start
  • Scan Modes
  • Threat Intelligence
  • Devil Gate Framework
  • Standalone Scripts
  • CI/CD Integration
  • Response Playbook
  • IOC Reference
  • Disclaimer
  • Limitations
  • Integrity Verification
  • License

Why This Exists

On March 31, 2026, the widely-used axios npm package (v1.14.1 and v0.30.4) was compromised through a maintainer account takeover attributed to UNC1069/DPRK-APT (per Google Threat Intelligence Group). The attack injected a phantom dependency ([email protected]) that deployed a cross-platform RAT via postinstall scripts, disguised as legitimate system processes.

Supply Chain Guard (SCG) was built during the incident to provide:

  1. Immediate detection — Is my machine or project affected right now?
  2. Structured assessment — How severe is it? What's the blast radius?
  3. Guided response — Step-by-step remediation with safety confirmations
  4. Ongoing defense — An 8-gate verification framework to prevent recurrence

How SCG Differs from Existing Tools

SCG is not a replacement for existing security tools. It combines multiple detection layers with a structured verification framework and guided remediation — designed for use during active incidents or as a periodic check alongside your existing tooling.

ToolWhat it doesHow SCG relates
npm auditChecks registry for known vulnerabilitiesSCG includes npm audit as its L1 layer, then adds IOC filesystem/network scanning, malicious package detection, and a structured response workflow on top
osv-scannerScans lockfiles against Google's OSV databaseSCG includes OSV as its L2 layer. osv-scanner doesn't check for RAT artifacts on your filesystem or active C2 connections
Snyk / Socket.devCommercial SaaS with real-time monitoring, PR checks, license scanningSCG is free, local-first, no account required, no data sent to third parties. Designed for immediate incident response rather than ongoing monitoring
Manual IRAd-hoc investigation with custom scriptsSCG provides a repeatable framework (8 verification gates, convergence loop, severity matrix) instead of one-off checklists that vary per incident

When to use SCG:

  • A supply chain incident just dropped and you need to check your machines and projects right now
  • You want a structured, repeatable process for verifying that a compromise has been fully addressed
  • You need a lightweight check that runs locally without SaaS dependencies

When to use something else:

  • You need continuous real-time monitoring → Snyk, Socket.dev
  • You need license compliance scanning → Snyk, FOSSA
  • You need coverage beyond npm/yarn → osv-scanner (supports pip, cargo, go, etc.)

What SCG Is (and Isn't)

We'd rather be honest about the boundaries than oversell. SCG is three things:

  1. An incident-response playbook, as code. When a named incident drops (axios RAT, Shai-Hulud, a fresh CVE), SCG turns "am I affected, and if so what do I do?" into an executable checklist — 8 verification gates, a severity matrix, and a remediation script where every destructive action needs explicit [y/N] confirmation. This is its primary value: the fast, structured first response that commercial monitoring tools aren't shaped for.

  2. An orchestrator of existing OSS scanners. The L1/L2 layers wrap npm audit / pip-audit / osv-scanner. Most of the raw detection power is borrowed; SCG's contribution is bundling them into one pass, adding filesystem/IOC checks the registry tools don't do, and making the output readable and actionable.

  3. Documentation of real design-hygiene lessons (SKILL.md §D.7) — things we actually hit or investigated: MCP transport choice, GCP default-SA hardening, install-time execution vectors, and threats that target AI dev tooling (Shai-Hulud reading .claude/settings.json, SANDWORM_MODE poisoning MCP configs). This niche — supply-chain hygiene for AI-assisted development — is where SCG is genuinely differentiated.

What SCG is deliberately NOT

  • Not a coverage competitor. The threat database (SKILL.md D.2, the L3 static lists) is hand-maintained — it holds the incidents we've read about, not the tens of thousands of malicious packages a live commercial feed tracks. A hand-curated list cannot keep pace with the real rate of new threats, and we don't pretend it does.
  • Not a behavioral analysis engine. SCG matches known patterns. Obfuscated payloads and true zero-days with no public advisory are out of scope by construction.
  • Not continuous monitoring. It's a point-in-time check you run during an incident or as a periodic sweep — not a service watching your dependency graph.

Where SCG is headed

Because a hand-curated database can't win on coverage, we're intentionally investing where SCG is hard to replace rather than where it will always lose:

  • Deeper incident-response playbooks (#1) — better first-response ergonomics, more incident templates.
  • AI-development-environment hygiene (#3) — detection and guidance for threats aimed at Claude Code / Cursor / MCP servers and similar tooling, which commercial supply-chain scanners largely don't address.

The static threat DB (#2) will keep getting updated when notable incidents land, but it is explicitly not the direction we're trying to compete on.


Architecture

SCG follows a Domain-Driven Design (DDD) architecture with three layers:

Download Tool