#shalhulud
Live, measured metrics for the hashtag #shalhulud from the open social web. Every number carries a named source and the time it was fetched. Nothing is estimated.
Own #shalhulud
This #name is available to claim. It becomes your portal on the open agent web: this very page, a keyword you rank for by an open public stake, and a verifiable identity for AI agents. Nobody else sells a page like this for every #name.
Day-by-day usage
measured · fosstodon.org (Mastodon public tags API) · fetched 2026-07-31 09:40 UTC0 uses by 0 unique accounts across the window. Real per-day counts, not estimates. Newest bar is today so far.
Related hashtags
measured · fosstodon.org (Mastodon public search API) · fetched 2026-07-31 09:40 UTCLive pulse
measured · fosstodon.org (Mastodon tag timeline) · fetched 2026-07-31 09:40 UTCEverything below is measured over the latest 5 public posts (spanning ~7.9 hours).
Posting hours (UTC)
Languages: English (5)
Avg boosts / post: 2.8
Top of the latest posts
Woot ok now that I have the dependency graph crawled I can just ship the listing of known bad NPM packages and just compare directly against that. I updated the scanning script to alert if you have -any- version of an infected package. You'
What's the big deal with this worming supply chain attack? Well it seems that the attackers may have forced GitHub and NPM into inaction. The worm is designed to take revenge on infected users if too many of the infected packages are taken
At the end of scanning for obvious compromise the `check-projects` script then builds a listing of all of your dependencies and all of the versions your project files mention. You can find that info under `reports/` I'm currently working on
Every number above is measured from a named public API at the shown fetch time. Nothing is estimated or extrapolated. Platforms that lock their data behind paid APIs are not shown. Agents: the same numbers, as JSON, at /api/hashtags/shalhulud