
PolinRider
Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Documenting the internals of Fingerprint Pro's commercial agent, not the open-source FingerprintJS library

🧬 Extract and analyze contributors info from git repos

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

Neto | A tool to analyse browser extensions

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

Hunt for AI coding artifacts containing secrets.

NCC Code Navigator

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Command-line tool for fast searching of GitHub repositories, users, and commits to gather open-source intelligence and code-related information.

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server…

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner