Skip to main content
在 Manus 中运行任何 Skill
一键导入

supply-chain-malware-scanner

IoC-based local scanner and safe-eradication runbook generator for npm/PyPI supply-chain worm campaigns (Mini Shai-Hulud 1st/2nd, S1ngularity, lottie-player). Detects OS persistence (LaunchAgent/systemd/Scheduled Tasks), IDE-hook implants (.claude/.vscode/.github/workflows), lockfile-pinned malicious versions, and known C2/Session-Protocol exfil traces. Orchestrates persistence-first eradication and dependency-ordered credential rotation so revocation does not trigger the `rm -rf ~/` retaliation payload. Standalone — no orchestrator, sibling skill, or shared protocol files required.

概览

IoC-based local scanner and safe-eradication runbook generator for npm/PyPI supply-chain worm campaigns (Mini Shai-Hulud 1st/2nd, S1ngularity, lottie-player). Detects OS persistence (LaunchAgent/systemd/Scheduled Tasks), IDE-hook implants (.claude/.vscode/.github/workflows), lockfile-pinned malicious versions, and known C2/Session-Protocol exfil traces. Orchestrates persistence-first eradication and dependency-ordered credential rotation so revocation does not trigger the `rm -rf ~/` retaliation payload. Standalone — no orchestrator, sibling skill, or shared protocol files required.

安装命令
npx skills add https://github.com/simota/supply-chain-malware-scanner --skill supply-chain-malware-scanner

复制此命令并粘贴到 Claude Code 中以安装该技能

星标0
分支0
更新时间2026年5月13日 11:12
SKILL.md
readonly