Shai-Hulud

MITRE ATT&CK: S9008 View on attack.mitre.org

Aliases: Shai-Hulud

Malware type
worm, credential-stealer
Family
Malware family
Operating systems
linux, saas, windows
Related IoCs
105 (102 malicious)
Last IoC activity
2026-08-28 02:14:57
Profile updated
2026-07-07 14:34:24

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector

Context

Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM packages. It exploits CI/CD pipeline dependencies to propagate to victims and poisons the supply chain by publishing malicious packages. Once inside a victim environment, Shai-Hulud steals credentials and access tokens from compromised repository accounts and exfiltrates them to attacker-controlled servers via encoded GitHub Actions workflows.

Recent IoC activity

102 malicious indicators in Maltiverse are attributed to Shai-Hulud (S9008). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample afa5458077f5fe262d38867f20fc401a8a680da31daa328e33ee403741b1b0fe 2026-08-28 1
URL https://webhook.site/bb8ca5f6-4175-45d2-b042-fc9ebb8170b7 2026-08-06 2
file sample 1ac23cd9220efb68f0bc40c713e8cacefdad48dda90999d47afc6e5e94c6a5fb 2026-07-21 1
file sample d56336949a4e665e9d64eb783c5b5d7f280a685b618d439f7087ef88185053a5 2026-07-21 1
file sample ea10fe718d90f663a314d6ef861acf2c2e15d83304f6ecc085abc4a315419e42 2026-07-21 1
file sample eebe8bbb5d1f4641a83e29858ba043bb17a2ab2d7fa386ceb9195b840da4b426 2026-07-21 1
file sample 319a7b1a2ecebd3dabfe698ad3d956e86b224e31d97b7786745a6f6741f0a622 2026-07-21 1
URL https://filev2.getsession.org/file/ 2026-07-18 1
file sample 4b2399646573bb737c4969563303d8ee2e9ddbd1b271f1ca9e35ea78062538db 2026-07-18 1
file sample f410c3e6b60765e79e90201dc8f8cc1c676d3f46ce1411ae705680fef47548f0 2026-07-18 1
file sample 709a3cd5663bbd227f108298f7c19ba5bc7ca13bde1283436802b47e75ac2d30 2026-07-18 1
file sample 80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac 2026-07-18 1
file sample de0e25a3e6c1e1e5998b306b7141b3dc4c0088da9d7bb47c1c00c91e6e4f85d6 2026-07-18 1
file sample 660c55fb8408d0705e535f4758296fca1b2f0dbceebd142117e1e388c6e1fb16 2026-07-18 1
file sample 75826adfa3c2b55e4183924613a5129bbbea8c43bb1f0fe846d42263b6126ad4 2026-07-18 1
file sample 83a650ce44b2a9854802a7fb4c202877815274c129af49e6c2d1d5d5d55c501e 2026-07-18 1
file sample aba1fcbd15c6ba6d9b96e34cec287660fff4a31632bf76f2a766c499f55ca1ee 2026-07-18 1
file sample cd8436708d368f1aa4fbe9f4ca905fb9a99afec52ca3e794ef12aebab782226d 2026-07-18 1
file sample 5ae8b2343e97cc3b2c945ec34318b63f27fa2db1e3d8fbaa78c298aa63db52ed 2026-07-18 1
file sample 81d2a004a1bca6ef87a1caf7d0e0b355ad1764238e40ff6d1b1cb77ad4f595c3 2026-07-18 1

Detection coverage

  • 754 Sigma rules

Malware & tools used

  • Sudo and Sudo Caching (attack-pattern)
  • Systemd Service (attack-pattern)
  • Delay Execution (attack-pattern)
  • Poisoned Pipeline Execution (attack-pattern)
  • Data Destruction (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Compromise Software Dependencies and Development Tools (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Unix Shell (attack-pattern)
  • Cloud Accounts (attack-pattern)
  • Cloud Secrets Management Stores (attack-pattern)
  • Ignore Process Interrupts (attack-pattern)
  • Automated Collection (attack-pattern)
  • Web Protocols (attack-pattern)
  • Code Repositories (attack-pattern)
  • Exfiltration to Code Repository (attack-pattern)
  • Break Process Trees (attack-pattern)
  • Steal Application Access Token (attack-pattern)
  • Account Manipulation (attack-pattern)
  • Subvert Trust Controls (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Installer Packages (attack-pattern)
  • Upload Malware (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Shai Hulud (report)
  • x.com — 2005356174275760277 (report)
  • zscaler.com — Shai Hulud V2 Poses Risk Npm Supply Chain (report)
  • zscaler.com — Mitigating Risks Shai Hulud Npm Worm (report)
  • reversinglabs.com — Shai Hulud Worm Npm (report)
  • wiz.io — Shai Hulud Npm Supply Chain Attack (report)
  • MITRE ATT&CK — S9008 (report)
  • socket.dev — Shai Hulud Strikes Again V2 (report)
  • socket.dev — Tinycolor Supply Chain Attack Affects 40 Packages (report)
  • Palo Alto Unit 42 — Npm Supply Chain Attack (report)
  • aikido.dev — S1Ngularity Nx Attackers Strike Again (report)
  • Microsoft — Shai Hulud 2 0 Guidance For Detecting Investigating And Defending Against The Supply Chain Attack (report)
  • netskope.com — Shai Hulud 2 0 Aggressive Automated One Of Fastest Spreading Npm Supply Chain Attacks Ever Observed (report)

External references