Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

ToruAI/security-tools

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

7 Commits

Repository files navigation

supply-chain-tools

Open detection and response tools from ToruAI .

When a new supply chain threat hits, we build a scanner and share it. No gatekeeping.


Tools

WAVESHAPER.V2 RAT detector — axios npm supply chain compromise (March 31, 2026)

Detects signs of the Sapphire Sleet / UNC1069 (DPRK) attack on the axios npm package. ~100M weekly downloads. ~600K installs during the 3-hour exposure window.

Script Platform
axios-scan.sh macOS, Linux
axios-scan.ps1 Windows (PowerShell)

Advisory: GHSA-fw8c-xr5c-95f9


Philosophy

Supply chain attacks are getting faster and more targeted. Detection shouldn't be paywalled or buried in enterprise dashboards.

We release tools as threats emerge. If you use them, let us know — we iterate.


ToruAI — AI systems for operational intelligence.

About

Open detection and response tools from ToruAI. When a new supply chain threat hits, we build a scanner and share it.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

Contributors

AltStyle によって変換されたページ (->オリジナル) /