Skip to content
#

credential-theft

Here are 6 public repositories matching this topic...

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Dec 4, 2025
  • TypeScript

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger retry storms, bypass TLS validation, and request unauthorized entitlements. Confirmed on iOS 18.6.2 with potential iCloud-based propagation.

  • Updated Nov 6, 2025

Improve this page

Add a description, image, and links to the credential-theft topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the credential-theft topic, visit your repo's landing page and select "manage topics."

Learn more