Closed Circuit Consultants · Las Vegas, NV · remote US

Did a poisoned package get into your repos? We check, clean, and gate CI.

A fixed-fee sweep for npm worms like Shai-Hulud: every repository, every branch, every lockfile. If we find it, we purge it and hand you the rotation list. Then we put dependency scanning and a malware gate in CI so it cannot walk back in.

Security in the build

Free 30-minute call. Written findings in 48 hours after read access. Fixed fee.

How it starts

Call → 48h sweep findings → clean and gate

  1. 1. Free 30-minute call. How many repositories, which package managers, which CI, who can publish.
  2. 2. 48-hour findings you keep. What the sweep found, repo by repo, with evidence. If it is clean, it says so.
  3. 3. Clean and gate. If we found something: containment, history purge, and the rotation list. Either way: SCA and a malware gate in CI, fixed fee.

What the sweep covers

  • Git history on every branch: known worm signatures, base64 payloads, code hidden behind whitespace in config files, and known payload files checked by hash.
  • package.json lifecycle scripts: preinstall, postinstall, and prepare hooks that fetch or run unknown code.
  • Signs of active compromise: rogue self-hosted GitHub Actions runners, exfiltration webhooks, and credential scanners run inside CI.
  • Secrets in the tree and in history: cloud keys, GitHub tokens, Stripe keys, private keys.
  • A CycloneDX SBOM for every repository, so you know what you ship.
  • CI workflow review: pull_request_target triggers, cache sharing across forks, and how publish tokens are minted.

npm first. Composer, PyPI, Go modules, and NuGet lockfiles are covered by the SBOM and the secret scan.

Then the gate

SCA on every pull request

Dependency scanning (Snyk or the tool you already pay for) wired into CI, with a severity bar your team agrees to.

Malware and obfuscation check

A pull-request check that blocks known worm signatures and whitespace-hidden code before merge.

Release-age cooldown

New package releases wait before your installs will take them, with first-party publishers excluded, so a compromised release is not installed the hour it ships.

Pre-commit scan

Secrets, malicious dependency behavior, and obfuscation caught on the developer machine, before anything reaches a remote.

Proof

Who has done this

We wrote the scanner

sandtrace, a Rust tool we built: codebase audit with 50+ secret rules and 30 obfuscation rules, CycloneDX SBOM generation, sandboxed installs with syscall tracing, and credential-file monitoring.

Worm detect-and-purge tooling

A seven-phase git-history audit, a history purge for confirmed payloads, multi-repo scanning, and a GitHub Actions gate against reinfection.

Enterprise-scale remediation

Sean O'Dea led Kaseya's 2025 vulnerability remediation: 100,000+ findings and 2,000,000+ fixes across 2,000+ repositories, with Snyk and Wiz wired into CI across acquired engineering groups.

Security people, not a scanner vendor

CISSP and GIAC GPEN on the team. We read the code, and we fix it. See security in the build.

Questions

What is Shai-Hulud?

A self-replicating npm worm first seen in September 2025. It hides code in JavaScript and TypeScript config files behind whitespace, steals cloud and CI credentials, registers rogue GitHub Actions runners, and spreads to other packages.

We already run Dependabot or Snyk. Is that enough?

Those tell you about known-vulnerable versions. A poisoned release is brand new and is not in an advisory database when it installs. The sweep looks for payloads and behavior, not just version numbers. We keep your scanner and add the gate it does not cover.

Does package provenance protect us?

Not by itself. The May 2026 Mini Shai-Hulud releases carried valid build provenance. Provenance says how a package was built, not whether the code is honest. The controls that hold are human gates at merge, at privileged workflows, and at publish-token mint.

Do you need our secrets?

No. We need read access to the repositories and the CI configuration. If we find a compromise, you get the rotation list in order, and we can walk your team through it on a call.

What does it cost?

A fixed fee set by repository count on the free call. Cleanup, if needed, is scoped from the findings. The CI gate is a fixed-fee install.

Find out before the next release does.

Book the free call. Bring your GitHub or GitLab org name and a repo count.

Closed Circuit Consultants · SOC LLC d/b/a · Las Vegas, NV · remote across the US