You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Supply-chain malware scanner for Git repos. Finds droppers committed into the repo itself — the kind npm audit can't see because there's no malicious dependency. Runs on git clone or when VS Code opens the folder. Kills the loader, scans every repo you can reach, purges it from history.
Static malware analysis of SC Factory X (SCFX), a WordPress backdoor that hides its C2 in an Ethereum smart contract (EtherHiding). Includes IOCs and a cleanup guide.
Detects and removes the PolinRider supply-chain malware from developer machines and git repositories, then keeps watching. One 362 KB binary, zero dependencies, Windows/macOS/Linux.