#sha1hulud
Live, measured metrics for the hashtag #sha1hulud from the open social web. Every number carries a named source and the time it was fetched. Nothing is estimated.
Own #sha1hulud
This #name is available to claim. It becomes your portal on the open agent web: this very page, a keyword you rank for by an open public stake, and a verifiable identity for AI agents. Nobody else sells a page like this for every #name.
Day-by-day usage
measured · fosstodon.org (Mastodon public tags API) · fetched 2026-07-30 08:07 UTC0 uses by 0 unique accounts across the window. Real per-day counts, not estimates. Newest bar is today so far.
Related hashtags
measured · fosstodon.org (Mastodon public search API) · fetched 2026-07-30 08:07 UTCLive pulse
measured · fosstodon.org (Mastodon tag timeline) · fetched 2026-07-30 08:07 UTCEverything below is measured over the latest 28 public posts (spanning ~176 hours).
Posting hours (UTC) — busiest: 19:00
Languages: English (27) · German (1)
Avg boosts / post: 2.5
Top of the latest posts
#Breaking There's an active nodejs supply chain attack going around. From the looks of it many of these compromised packages have been mitigated but quite a few have not. https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24 #nodejs #cy
GitHub has almost finished taking down the stolen data posted by the Sha1-Hulud npm/github worm. I only see about 400 repos remaining of the around 23k created by the worm. This was the most visible evidence of the exploit, just because we
#sha1hulud has me so very spooked, that I dare not open any #electron apps and purged many of my dot files out of sheer paranoia. It is a scenario I dreaded for a long time. Fortunately, I never trusted vscode extensions and have disabled a
Every number above is measured from a named public API at the shown fetch time. Nothing is estimated or extrapolated. Platforms that lock their data behind paid APIs are not shown. Agents: the same numbers, as JSON, at /api/hashtags/sha1hulud