
gha-lab-a815a82f03-1
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction

GitHub Actions workflow sandbox for CVE-2026-45132 reproduction


A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Find log4j for CVE-2021-44228 on some places * Log4Shell

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Hashes for vulnerable LOG4J versions

La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y…

CVE-2024-3094 XZ Backdoor Detector


Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…


This is an incident response playbook we created for the Vercel April 2026 compromise

Portable security rules for the action boundary of AI agents