supply-chain-malware-scanner
IoC-based local scanner and safe-eradication runbook generator for npm/PyPI supply-chain worm campaigns (Mini Shai-Hulud 1st/2nd, S1ngularity, lottie-player). Detects OS persistence (LaunchAgent/systemd/Scheduled Tasks), IDE-hook implants (.claude/.vscode/.github/workflows), lockfile-pinned malicious versions, and known C2/Session-Protocol exfil traces. Orchestrates persistence-first eradication and dependency-ordered credential rotation so revocation does not trigger the `rm -rf ~/` retaliation payload. Standalone — no orchestrator, sibling skill, or shared protocol files required.
2026-05-13