
hexora
Static analysis of malicious Python code

Static analysis of malicious Python code

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during…

Vulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can…

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

Detection rules for the Claude Code source leak : 16 Sigma rules, Splunk, Elastic, YARA. Lab-validated on GOAD Light DC02.

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

Threat hunting command system for agentic IDEs

OpenIOC rules to facilitate hunting for indicators of compromise

This Repository Talks about the Follina MSDT from Defender Perspective

Extracts selected MISP attributes, including IP addresses, URLs, and hashes, into reusable output files.


CVE-2023-34362-IOCs. More information on Deep Instinct's blog site.