A bash script to detect indicators of compromise from the SHA1-hulud npm supply chain attack.
SHA1-hulud is a supply chain attack targeting npm packages discovered in late 2025. Attackers compromise legitimate npm maintainer accounts and publish malicious versions that execute code during npm install.
Reference: https://thehackernews.com/2025/11/second-sha1-hulud-wave-affects-25000.html