
ThreatExchange
Trust & Safety tools for working together to fight digital harms.

Trust & Safety tools for working together to fight digital harms.

Clusters and elements to attach to MISP events or attributes (like threat actors)

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Defense Against the Shai-Hulud Supply Chain Attack

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Curated repository of Indicators of Compromise (IOCs), attack source IPs, and Snort/Suricata detection rules for Log4Shell (CVE-2021-44228) attacks.

Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack