Best Products
Launches
Launch archive
Most-loved launches by the community
Launch Guide
Checklists and pro tips for launching
News
Newsletter
The best of Product Hunt, every day
Stories
Tech news, interviews, and tips from makers
Changelog
New Product Hunt features and releases
Forums
Forums
Ask questions, find support, and connect
Kitty Points Leaderboard
The highest scoring community members
Streaks
The most active community members
Events
Meet others online and in-person
Advertise
Subscribe
Sign in
Clear text
recent
p/octoscope
by
Giovambattista Fazioli
•
2mo ago
octoscope v0.20.0 — Integrity: scan your repos for the supply-chain worm 🔍
... Shai-Hulud / Miasma worm has been quietly pushing itself into people's GitHub repos including real, well-known OSS projects where it auto-runs the moment you open the repo in an AI editor (Claude / Cursor / Gemini /
VS
Code) or install it, then harvests your tokens. It lives in the GitHub source, not the npm registry, so a lockfile audit never sees it. octoscope already points at the repos you own, so this release teaches it to look. @icflorescu What ... ... signal alone reaches the scary tiers so a healthy repo reads clean and a real implant reads likely compromised. The report also lists every auto-executing file in the repo plus per-branch commit-tip provenance, so you
know
1
10
Subscribe
Sign in