Shai-Hulud
MITRE ATT&CK: S9008 View on attack.mitre.org
Aliases: Shai-Hulud
- Malware type
- worm, credential-stealer
- Family
- Malware family
- Operating systems
- linux, saas, windows
- Related IoCs
- 105 (102 malicious)
- Last IoC activity
- 2026-08-28 02:14:57
- Profile updated
- 2026-07-07 14:34:24
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Context
Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM packages. It exploits CI/CD pipeline dependencies to propagate to victims and poisons the supply chain by publishing malicious packages. Once inside a victim environment, Shai-Hulud steals credentials and access tokens from compromised repository accounts and exfiltrates them to attacker-controlled servers via encoded GitHub Actions workflows.
Recent IoC activity
102 malicious indicators in Maltiverse are attributed to Shai-Hulud (S9008). The 20 most recently updated:
Detection coverage
- 754 Sigma rules
Malware & tools used
- Sudo and Sudo Caching (attack-pattern)
- Systemd Service (attack-pattern)
- Delay Execution (attack-pattern)
- Poisoned Pipeline Execution (attack-pattern)
- Data Destruction (attack-pattern)
- Credentials In Files (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Compromise Software Dependencies and Development Tools (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Unix Shell (attack-pattern)
- Cloud Accounts (attack-pattern)
- Cloud Secrets Management Stores (attack-pattern)
- Ignore Process Interrupts (attack-pattern)
- Automated Collection (attack-pattern)
- Web Protocols (attack-pattern)
- Code Repositories (attack-pattern)
- Exfiltration to Code Repository (attack-pattern)
- Break Process Trees (attack-pattern)
- Steal Application Access Token (attack-pattern)
- Account Manipulation (attack-pattern)
- Subvert Trust Controls (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Installer Packages (attack-pattern)
- Upload Malware (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Shai Hulud (report)
- x.com — 2005356174275760277 (report)
- zscaler.com — Shai Hulud V2 Poses Risk Npm Supply Chain (report)
- zscaler.com — Mitigating Risks Shai Hulud Npm Worm (report)
- reversinglabs.com — Shai Hulud Worm Npm (report)
- wiz.io — Shai Hulud Npm Supply Chain Attack (report)
- MITRE ATT&CK — S9008 (report)
- socket.dev — Shai Hulud Strikes Again V2 (report)
- socket.dev — Tinycolor Supply Chain Attack Affects 40 Packages (report)
- Palo Alto Unit 42 — Npm Supply Chain Attack (report)
- aikido.dev — S1Ngularity Nx Attackers Strike Again (report)
- Microsoft — Shai Hulud 2 0 Guidance For Detecting Investigating And Defending Against The Supply Chain Attack (report)
- netskope.com — Shai Hulud 2 0 Aggressive Automated One Of Fastest Spreading Npm Supply Chain Attacks Ever Observed (report)
External references
- mitre-attack — S9008
- Aikido Shai-Hulud September 2025
- Netskope Shai-Hulud November 2025
- Palo Alto Unit 42 Shai-Hulud November 2025
- Wiz Shai-Hulud September 2025
- Microsoft Shai-Hulud December 2025
- Socket Shai-Hulud November 2025
- Socket Shai-Hulud Trufflehog September 2025
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy