gstack/cso
LYH e7af1929c0 feat(cso): Phase 8 Tier 3 — mini-shai-hulud campaign rules (comprehensive mode)
Adds 4 detection rules for the 2026-05-11 npm/PyPI supply chain campaign
(GHSA-g7cv-rxg3-hmpx / CVE-2026-45321) into Phase 8 (Skill Supply Chain).

- R7 (Claude Code settings hook injection — /proc/*/mem read pattern)
- R8 (obfuscated payload heuristic — _0x patterns + crypto-decode)
- R9 (auto-run persistence bridge — manifest-undeclared file referenced
  by hook or tasks.json runOn: folderOpen)
- R12 (Session-protocol C2 deny-list — executable context only)

All rules surface only under /cso --comprehensive with TENTATIVE marking;
daily mode's 8/10 zero-noise contract is preserved.

Closes Phase 8 gaps for IDE-config infection vectors that the existing
generic-pattern matching (curl/wget/exfiltrat/IGNORE PREVIOUS) does not
catch. No new skill, no new phase, no scope-flag changes (per #1011).
2026-05-15 20:49:08 +09:00
..
ACKNOWLEDGEMENTS.md feat: /cso v2 — infrastructure-first security audit (v0.11.6.0) (#384) 2026-03-23 06:57:22 -07:00
SKILL.md feat(cso): Phase 8 Tier 3 — mini-shai-hulud campaign rules (comprehensive mode) 2026-05-15 20:49:08 +09:00
SKILL.md.tmpl feat(cso): Phase 8 Tier 3 — mini-shai-hulud campaign rules (comprehensive mode) 2026-05-15 20:49:08 +09:00