Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors shai-hulud

Also known as: tracked as, Mini Shai-Hulud, a worm

Description

Shai‑Hulud is operated by the TeamPCP group and has evolved into a self‑replicating worm that leverages modern supply‑chain attack vectors across multiple ecosystems. It injects malicious post‑install lifecycle hooks—such as "setup_bun.js"—into popular npm packages to install the Bun JavaScript runtime, which then runs a multi‑stage credential stealer targeting local configuration files, environment variables, and cloud secret stores including AWS Secrets Manager, GCP Secret Manager, and Azure Key Vault. Beyond credential theft, Shai‑Hulud abuses GitHub Actions by injecting workflow files (e.g., "discussion.yaml") that run during CI/CD pipelines to exfiltrate secrets over HTTP/HTTPS, enumerate OIDC tokens from runner memory, and deploy self‑hosted runners under the attacker’s control. The malicious code also tamperes with system services—modifying systemd-resolved, flushing iptables, and in worst cases destroying writable home directories via overwrite or shred commands to hide activity. The actor demonstrates cross‑ecosystem propagation by targeting both npm/PyPI packages and IDE configuration files. It exploits compromised vulnerability scanners, misconfigured GitHub Actions, and malicious tarball distributions while using AI prompt injection to evade LLM‑based code scanners. By publishing malicious packages with valid SLSA provenance, Shai‑Hulud breaks trust chains at the highest assurance level, creating a highly resilient supply‑chain attack capable of widespread contamination.

Goals & Targeting

Targeted Sectors

Government
Defense
Critical infrastructure
Financial services
Information technology
Oil gas
Telecommunications
Non profit
Think tank

Targeted Countries / Regions

US
SA
KP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 23 hours ago

Executive Summary

Shai‑Hulud is a supply‑chain worm that propagates through npm/PyPI packages and malicious GitHub Actions workflows, harvesting credentials from cloud secret stores and exfiltrating them via encoded payloads. It creates public repositories on victims’ accounts to leak stolen secrets and can manipulate system services for persistence or destructive impact. The actor demonstrates advanced evasion techniques such as AI‑prompt injection and SLSA provenance spoofing, making detection challenging.

Goals & Targeting

Shai‑Hulud primarily seeks financial gain by harvesting credential material that can be sold or leveraged for further compromise. The actor targets a broad spectrum of sectors—including government, defense, critical infrastructure, financial services, information technology, oil & gas, telecommunications, and non‑profits—across the United States, Saudi Arabia, and North Korea. These victims are chosen for their reliance on open‑source ecosystems and cloud environments, maximizing the likelihood of finding exposed secrets in npm/PyPI packages, GitHub Actions pipelines, and cloud secret stores.

Enhanced Description

Key Capabilities

  • Propagates via malicious npm and PyPI package lifecycle hooks (postinstall/preinstall)
  • Injects compromised GitHub Actions workflows to exfiltrate credentials
  • Harvests secrets from AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and OIDC tokens
  • Creates public repositories on victim accounts to leak stolen data
  • Utilizes Bun JavaScript runtime for multi‑stage credential theft
  • Employs triple‑layer base64 encoding to evade detection
  • Modifies system services (systemd-resolved, iptables) for persistence or destructive impact
  • Uses AI prompt injection to bypass LLM‑based scanners and generate malicious packages with valid SLSA provenance

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Privilege Escalation
Collection
Defense Evasion
Exfiltration
Impact
Discovery

ATT&CK Techniques

T1071
T1071.001
T1105
T1106
T1027
T1036
T1041
T1078
T1098
T1119
T1543
T1552.002
T1552.003
T1552.004
T1552.006
T1552.007
T1555
T1564
T1567
T1567.001
T1574
T1677

Software / Tooling

Shai-Hulud
Mini Shai-Hulud
Node.js
Bun
PowerShell
curl
TruffleHog
Agent Tesla
Pysa
Carbon

Campaigns & Victims

Since its emergence, Shai‑Hulud has infected more than 25,000 GitHub repositories and distributed malicious npm packages on a daily basis. Campaigns exhibit high operational tempo with rapid seed and spread cycles; the actor leverages public supply‑chain channels to reach new victims quickly. While primarily focused on credential theft for financial exploitation, Shai‑Hulud’s destructive capabilities—such as overwriting user home directories—indicate potential pivoting toward broader impact attacks. Early iterations of the worm were limited to npm packages, but later versions expanded into PyPI and IDE configuration files, demonstrating adaptability.

IOC Patterns

  • Public GitHub repository named "Shai‑Hulud" containing leaked credentials or malicious code
  • Encoded (double or triple base64) GitHub Actions workflow files used for exfiltration
  • Stolen .npmrc or CI/CD token entries revealed in public repos
  • Use of AWS/GCP metadata endpoint URLs to harvest instance credentials
  • Bun runtime executable "bun.exe" or "bun.js" distributed via malicious npm packages

Recommended Actions

  • Implement and enforce strict SBOM validation on all package deployments; block malicious npm/PyPI artifacts pre‑installation.
  • Deploy continuous monitoring for unauthorized GitHub Actions workflow changes, repository creation, and publicization of private repos.
  • Audit and restrict publishing rights for package registries to limit misuse and self‑propagation. Enforce least privilege in CI/CD environments (e.g., protect /etc/sudoers.d, disable root escalation where not needed).
  • Enable endpoint protection with detections for systemd-resolved tampering and iptables flushing; monitor for destructive file overwrites with shred or delete operations.
  • Integrate threat intelligence feeds to detect double/triple‑encoded data patterns and suspicious base64‑obfuscated payloads. Regularly review cloud metadata endpoints for abnormal queries, and enforce tight IAM roles for instance service accounts.

ATT&CK Techniques

Initial Access
1 technique
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 5 Domain 14 Filename 1

References

  1. www.microsoft.com — Cited by web research for: Mini Shai-Hulud
  2. attack.mitre.org — Cited by web research for: T1552
  3. attack.mitre.org — Cited by web research for: T1552.002
  4. unit42.paloaltonetworks.com — Cited by web research for: Payload
  5. www.zscaler.com — Cited by web research for: Carbon
  6. www.trendmicro.com — Cited by web research for: whoami
  7. www.zscaler.com — Cited by web research for: North Korea

Intel Summary

43

Techniques

53

Tools

0

Campaigns

40

IOCs

0

Observed Data

15

Tactics

Tags

APT
supply_chain_attacks
malware

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.