
OreNPMGuard
Defense Against the Shai-Hulud Supply Chain Attack

Defense Against the Shai-Hulud Supply Chain Attack

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Clusters and elements to attach to MISP events or attributes (like threat actors)

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

ThePhish: an automated phishing email analysis tool

Trust & Safety tools for working together to fight digital harms.

Curated repository of Indicators of Compromise (IOCs), attack source IPs, and Snort/Suricata detection rules for Log4Shell (CVE-2021-44228) attacks.

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

A tool for simplifying the process of researching IOCs.

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

Educational analysis of the Log4Shell (CVE-2021-44228) vulnerability, detailing its exploitation in a cryptocurrency mining campaign with IoCs, MITRE…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…