
bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

A collection of awesome resources related AI security

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Curated repository of documented firmware supply chain attacks, featuring IoCs, detection tools, and references to help defenders understand and…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

Curated vulnerability writeups with full technical analysis, proof-of-concept scripts, IOC listings, and remediation guidance for real-world software…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Regla YARA para detectar el backdoor de liblzma en XZ Utils 5.6.0/5.6.1 (CVE-2024-3094).

Shell script to detect the CVE-2024-3094 backdoor in XZ Utils by checking for malicious code in liblzma build artifacts and identifying affected…

List of company advisories log4j

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Hashes for vulnerable LOG4J versions