Guides

Each guide answers one question completely: what the risk is, what to do step by step, what the tools catch, and what they do not.

How to catch a supply-chain attack that npm audit misses

npm audit, OSV-Scanner and Snyk match dependencies against published advisories. An attack committed into a repository, or one not yet reported, is invisible to them. How to add indicator-based checks with am-i-hacked to a dev script, a git pull and CI.

How to check whether your developer machine is compromised

A read-only audit of a macOS or Linux developer machine with am-i-hacked --system: login persistence and code signatures, crontab, shell startup files, AI coding tool config, running processes and the folders tooling installs code into.

Is this macOS login item or background item malware?

How to decide whether a macOS login item or "Background Items Added" entry is legitimate: map the name to its launchd plist, check the program's code signature and Team ID against the vendor, read script payloads without running them, and preserve evidence.

Which browser extension is recording my screen?

macOS says "Brave Browser is recording your screen" but not which tab or extension. am-i-being-recorded reads Chromium-family browser profiles and names the extensions that can capture the display or a tab.

How to prevent SSRF when your server fetches a user-supplied URL

A checklist for server-side request forgery (SSRF): allow only http and https on ports 80 and 443, resolve the host and reject every non-public address, follow redirects by hand, cap size and time, and connect to the address you checked. With hostile test inputs and Semgrep rules.