Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
shai-hulud-scan — Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs | Kitploit
Tools/GitHubGitHub/shayr1/shai-hulud-scan
Indicator of Compromise (IOC) ManagementVulnerability AnalysisForensicsMalware AnalysisThreat IntelligenceSupply Chain SecurityLearning & EducationIncident Response
GitHubshayr1/shai-hulud-scan

shai-hulud-scan

Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs

View Repository
1154 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

shai-hulud-scan

A Claude Code skill that scans machines for indicators of compromise (IOCs) from the Mini Shai-Hulud supply chain worm (CVE-2026-45321, CVSS 9.6).

What is Mini Shai-Hulud?

A self-propagating supply chain worm that compromised 170+ npm/PyPI packages on May 11, 2026 - including @tanstack/*, @mistralai/*, @uipath/*, and @opensearch-project/*. It steals credentials, persists through developer tools, and installs a dead-man's switch that wipes your home directory if you revoke tokens before removing it.

Threat actor: TeamPCP

What this skill does

Runs 5 diagnostic passes checking for worm artifacts. Fully transparent - every command is shown before execution and nothing runs without your explicit approval.

PassCheckWhy
1Dead-man's switch (gh-token-monitor)Wipes ~/ if tokens are revoked before removal
2Persistence hooks (Claude Code, VS Code, GitHub Actions)Re-executes worm on IDE launch
3Malicious files (router_init.js, tanstack_runner.js)Payload persists after package removal
4Compromised package versions in lockfilesAffected @tanstack, @mistralai, @uipath, @opensearch versions
5Network IOCs (opt-in)Active C2 connections and DNS resolution

How each pass works

  1. Explains what it checks and why it matters
  2. Shows you the exact shell commands it will run
  3. Asks for your approval before running anything
  4. Reports results: CLEAN, INFECTED, or SKIPPED
  5. If infected, prints remediation steps in the correct order

Cross-platform support

  • macOS - LaunchAgents, launchctl, lsof, shasum
  • Linux - systemd, ss, sha256sum
  • Windows WSL - Linux checks + PowerShell for Windows-side checks
  • Windows - PowerShell native (Get-ScheduledTask, Get-FileHash, Resolve-DnsName)

Install

As a Claude Code plugin

/plugin marketplace add shayr1/shai-hulud-scan
/plugin install shai-hulud-scan

Then run with: /shai-hulud-scan

Manual install

git clone https://github.com/shayr1/shai-hulud-scan.git /tmp/shai-hulud-scan
mkdir -p ~/.claude/skills/shai-hulud-scan
cp /tmp/shai-hulud-scan/SKILL.md ~/.claude/skills/shai-hulud-scan/SKILL.md

Then run with: /shai-hulud-scan

Example output

Detected platform: macOS. All commands below are tailored for this environment.

### Pass 1: Dead-Man's Switch

The worm installs a daemon called `gh-token-monitor` that polls GitHub every
60 seconds. If it detects that your GitHub token has been revoked, it executes
`rm -rf ~/` - wiping your entire home directory.

Commands that will run:

  test -f ~/Library/LaunchAgents/com.user.gh-token-monitor.plist && echo "FOUND" || echo "NOT FOUND"
  launchctl list 2>/dev/null | grep gh-token-monitor || echo "NOT FOUND"
  test -f ~/.local/bin/gh-token-monitor.sh && echo "FOUND" || echo "NOT FOUND"

> Approve running these commands? [Approve / Skip]

Pass 1 - Dead-man's switch: CLEAN
## Scan Complete - Results

| Pass | Check                 | Result  |
|------|-----------------------|---------|
| 1    | Dead-man's switch     | CLEAN   |
| 2    | Persistence hooks     | CLEAN   |
| 3    | Malicious files       | CLEAN   |
| 4    | Compromised packages  | CLEAN   |
| 5    | Network IOCs          | SKIPPED |

CVE: CVE-2026-45321 | CVSS: 9.6 | Threat Actor: TeamPCP

IOC reference

File hashes (SHA256)

  • ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c - router_init.js
  • 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96 - tanstack_runner.js
  • 2258284d65f63829bd67eaba01ef6f1ada2f593f9bbe41678b2df360bd90d3df - setup.mjs

C2 infrastructure

  • git-tanstack.com (typosquat domain)
  • api.masscan.cloud (secrets exfiltration)
  • filev2.getsession.org (Session Protocol exfil)
  • 83.142.209.194 (mistralai credential stealer)

Persistence paths

  • ~/Library/LaunchAgents/com.user.gh-token-monitor.plist (macOS)
  • ~/.config/systemd/user/gh-token-monitor.service (Linux)
  • ~/.local/bin/gh-token-monitor.sh (macOS/Linux)
  • ~/.claude/router_runtime.js, ~/.claude/setup.mjs
  • .vscode/setup.mjs, .github/workflows/codeql_analysis.yml

Lockfile markers

  • voicproducoes (attacker npm account)
  • 79ac49eedf (orphan commit hash prefix)

Sources

  • The Hacker News - Mini Shai-Hulud Worm Compromises TanStack, Mistral AI & More
  • Wiz Blog - Mini Shai-Hulud Strikes Again
  • Snyk - TanStack npm Packages Hit by Mini Shai-Hulud
  • StepSecurity - TeamPCP's Mini Shai-Hulud Is Back

License

MIT

Download Tool