
thumper
jestasecurity
Thumper is an open-source tripwire for the Shai-Hulud npm worm. Plant fake-but-realistic credentials where the worm scans - the instant one is read, you know the box might be breached. Free and built in the open by Jesta.
AI 简介
Thumper 是一个开源的蜜罐凭证(honeytoken)监控平台,专用于检测 npm 供应链攻击(如 Shai-Hulud 蠕虫)中的凭据窃取行为。它通过在代码仓库、配置文件或环境变量中部署伪造但高度逼真的凭证(如 API 密钥、令牌),在凭证被读取的瞬间触发实时告警;所有凭证无实际权限,仅以“读取”为入侵信号。项目采用 Python 开发,支持 Docker 一键部署及 Kubernetes Helm 部署,提供可视化仪表盘与端点管理能力。适用于 DevSecOps 团队在软件开发、CI/CD 流水线和生产环境监控中主动防御供应链攻击。
Python
Apache License 2.0223
Stars
13
Forks
52
Watchers
31
Issues
Star 增长
今日0
近 7 天0
近 30 天+1
综合评分43.54
默认分支main