Vvanakor
Back to research
shippedGo★ 32025

Typosentinel

Supply chain attacks that scanners miss.

A supply chain security platform that goes well past basic typosquatting detection — catching build-time compromises, CI/CD infrastructure abuse, and runtime exfiltration patterns, without requiring Docker.

View on GitHub

Highlights

  • 01Build integrity: trojanized binaries, time-delayed activation, unsigned or suspicious signatures (SolarWinds / SUNBURST class).
  • 02CI/CD abuse: malicious GitHub Actions workflows, self-hosted runner backdoors, GitLab CI misconfigurations (Shai-Hulud class).
  • 03Runtime exfiltration: API calls from install scripts, CI-targeted environment-aware malware, periodic C2 patterns.
  • 04Published to Docker Hub, Go 1.24, MIT licensed.

Tags

supply-chainci-cdsbomgolangmalware-analysis